logo

Rules File Backdoor: AI Code Editors exploited for silent supply chain attacks

ID: 02449a51-cfa5-5c8e-be2a-975f46d00b1a

STIX ID: report--02449a51-cfa5-5c8e-be2a-975f46d00b1a

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2025-03-19

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Pillar Security reports a new supply-chain technique named “Rules File Backdoor” where attackers embed hidden Unicode and crafted prompts in shared rule files to coerce AI code editors (GitHub Copilot, Cursor) into producing backdoored or vulnerable code; the write-up includes technical details, a PoC video, and a responsible-disclosure timeline showing vendor responses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.