Attackers are crafting malicious AI instruction files to turn agents into criminal helpers


Moreover, this attack leaves no malicious binary on disk, does not inject code into other processes, and has no classic persistence mechanisms. As a result, it won’t be detected by EDRs or from a workstation monitoring perspective, because it looks like normal tool usage given that the agent itself is performing the exfiltration.

Exfiltration to external cloud-hosted databases

Mitiga’s researchers found and reported multiple examples of agent instruction file poisoning on GitHub repositories. None were popular repositories accessed by a large number of developers, but they don’t need to be. Links to these repositories could be sent to victims in targeted attacks, as has been seen in fake recruitment attacks where developers are asked during the interview process to clone GitHub projects containing malicious code.

One example was a DevOps repository containing poisoned .cursorrules and .github/copilot-instructions.md. The repository contained a full-stack application built with React + Vite frontend, along with Express API, PostgreSQL, nginx configuration, Docker containers, GitLab CI jobs, and AWS infrastructure setup files for Terraform and Terragrrunt. In other words, everything needed to deploy that application.

Leave a Reply

Your email address will not be published. Required fields are marked *