Opening SecureFlowRules File Backdoor: Supply Chain Attack on AI Coding Assistants
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

MITRE ATLAS mitre-atlas-cs0041

Rules File Backdoor: Supply Chain Attack on AI Coding Assistants

  • Autonomous Agents
  • AI Supply Chain
  • Model Poisoning & Integrity

Pillar Security researchers demonstrated how adversaries can compromise AI-generated code by injecting malicious instructions into rules files used to configure AI coding assistants like Cursor and GitHub Copilot. The attack uses invisible Unicode characters to hide malicious prompts that manipulate the AI to insert backdoors, vulnerabilities, or malicious scripts into generated code. These poisoned rules files are distributed through open-source repositories and developer communities, creating a scalable supply chain attack that could affect millions of developers and end users through compromised software. Vendor Response to Responsible Disclosure: - Cursor: Determined that this risk falls under the users' responsibility. - GitHub Copilot: Implemented a new security feature (https://github.blog/changelog/2025-05-01-github-now-provides-a-warning-about-hidden-unicode-text/) that displays a warning when a file's contents include hidden Unicode text on github.com.

Mapped threat techniques

Source

Updated