logo

GitHub Copilot 'CamoLeak' AI Attack Exfiltrates Data

ID: d961aaed-ebc5-5ca5-9a47-609a69ccf13f

STIX ID: report--d961aaed-ebc5-5ca5-9a47-609a69ccf13f

Feed Name: Dark Reading

Threat Score
50/100

Date Published: 2025-10-09

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

Researchers demonstrated a proof-of-concept called "CamoLeak" that combines prompt injection in GitHub Copilot with a creative bypass of GitHub's Camo image proxy: an attacker registers many 1x1 pixel images mapped to characters, injects a hidden prompt that causes Copilot to render sensitive values as a sequence of those images, and the attacker reads the image fetch order to reconstruct secrets. The technique can leak small, high-value items (tokens, keys, snippets), is technically non-trivial but limited in volume, and GitHub mitigated the risk by disabling image rendering in Copilot chat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.