Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securityleaked-secret-api-keycloud-service-vulnerabilitybuild-pipeline-compromise

RoguePilot Prompt-Injection Flaw in GitHub Codespaces Allowed Copilot to Leak `GITHUB_TOKEN`

Updated 3mo agoFirst seen Feb 25, 20262 sources

Microsoft patched an AI-mediated vulnerability in GitHub Codespaces dubbed RoguePilot (reported by Orca Security) that could let an attacker seize control of repositories by embedding hidden instructions in a GitHub issue. When a developer launched a Codespace from a malicious issue, the issue text could be automatically ingested by the built-in GitHub Copilot agent, enabling passive/indirect prompt injection that coerced the agent into executing attacker-directed actions and leaking sensitive credentials—most notably a privileged GITHUB_TOKEN—potentially enabling repository takeover and downstream supply-chain impact.

The disclosure reinforces a broader risk pattern where developer tools and AI agents become high-trust entry points for supply-chain compromise, as highlighted by commentary describing how dev-platform footholds can cascade into cloud and SaaS environments via token theft and trusted integrations. Separate reporting also notes increasing attacker speed and AI-enabled tradecraft, but those items are not specific to RoguePilot; the core actionable takeaway is that AI agents embedded in developer workflows can be manipulated through untrusted content (e.g., issues/PRs) unless strong isolation, least-privilege token scoping, and explicit user confirmation/guardrails prevent autonomous execution and secret exfiltration.

Share:
RoguePilot Prompt-Injection Flaw in GitHub Codespaces Allowed Copilot to Leak `GITHUB_TOKEN`
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Feb 24, 20264mo ago

Microsoft patched the RoguePilot issue after disclosure

Microsoft remediated the GitHub Codespaces/Copilot issue following responsible disclosure, closing the prompt-injection path described by Orca Security.

Orca Security disclosed RoguePilot in GitHub Codespaces

Orca Security revealed the RoguePilot flaw, showing that hidden prompt-injection instructions in a GitHub issue could manipulate Copilot in Codespaces and expose sensitive data such as a privileged GITHUB_TOKEN.

Google tracked the Salesloft-linked actor as UNC6395

Google identified and tracked the threat actor behind the Salesloft-related activity as UNC6395, adding attribution to the campaign.

Jan 30, 20265mo ago

GlassWorm campaign identified via malicious Open VSX updates

On January 30, 2026, researchers identified the GlassWorm campaign, in which compromised Open VSX publishing credentials were used to push malicious VS Code extension updates that harvested secrets.

Mar 11, 20251y ago

Drift OAuth tokens used to access 700+ Salesforce tenants

Using stolen Drift-related OAuth tokens, the attacker allegedly accessed data from more than 700 Salesforce customer tenants over roughly 10 days while blending in with normal integration traffic.

Mar 1, 20251y ago

Attacker pivoted from Salesloft GitHub into AWS environment

After the initial GitHub compromise, the attacker reportedly moved into Salesloft's AWS environment and obtained OAuth tokens tied to the Drift chatbot integration.

Attacker allegedly compromised Salesloft's GitHub organization

In March 2025, an attacker allegedly breached Salesloft's GitHub organization, beginning a SaaS supply-chain intrusion chain later linked to downstream customer data access.

Dec 1, 20224y ago

CircleCI disclosed a late-2022 compromise

CircleCI reported a compromise in late 2022, later cited as another major example of CI/CD and developer-environment supply-chain risk.

Apr 15, 20215y ago

Codecov Bash Uploader supply-chain compromise disclosed

Attackers compromised Codecov's Bash Uploader in a software supply-chain incident that became a notable precedent for later developer-tool compromises.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Affected products
1 linked
Github Copilot
Organizations
5 linked
NeuralTrustHiddenLayerMicrosoft CorporationGitHubOrca Security
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.