logo

Agents hooked into GitHub can steal creds – but Anthropic, Google, and Microsoft haven't warned users

ID: dabc10b8-45a7-5551-8442-151f9997c7f7

STIX ID: report--dabc10b8-45a7-5551-8442-151f9997c7f7

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-04-15

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Security researchers discovered and demonstrated a "comment-and-control" prompt-injection technique that hijacks AI agents running in GitHub Actions (Anthropic Claude Code Security Review, Google Gemini CLI Action, GitHub Copilot Agent) to exfiltrate API keys and GitHub tokens by injecting malicious instructions into PR titles, issue bodies, and hidden HTML comments. Vendors paid bounties but did not publish advisories, leaving users pinned to vulnerable versions at risk; recommended mitigations include least-privilege for agents, disabling unnecessary tools, and requiring human review for external contributions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.