logo

RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN

ID: ed82466a-c2e5-501e-a6b5-c5ae848da708

STIX ID: report--ed82466a-c2e5-501e-a6b5-c5ae848da708

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-02-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report describes an AI-mediated vulnerability called RoguePilot in GitHub Codespaces where hidden instructions embedded in GitHub issues can trigger Copilot to execute commands and exfiltrate privileged data such as the GITHUB_TOKEN; Microsoft patched the issue after responsible disclosure. It places RoguePilot in a wider context of emerging threats to LLM-based systems, including techniques to remove safety constraints (GRP-Obliteration), model/backdoor level interception (Agentic ShadowLogic), image jailbreak chains (Semantic Chaining), and the new malware-like class termed "promptware," all of which raise supply-chain, confidentiality, and integrity risks for developer workflows and agentic AI integrations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.