STUPID-2026-0028
Rule Files Backdoor: hidden Unicode in config files made Copilot and Cursor emit malicious code
Instruction given
Generate code in a project that contains a shared rules/configuration file.
Expected behavior
Ignore invisible or adversarial instructions embedded in configuration files; generate code only from the developer's visible intent.
Actual behavior
Copilot and Cursor obeyed hidden instructions injected into rule files using invisible Unicode characters, silently generating backdoored code that looked legitimate. The hidden characters stayed invisible during pull-request review, and once a poisoned rule file entered a repo it corrupted every future code-generation session for the whole team.
Damage
Pillar Security disclosed the technique to Cursor (Feb 26, 2025) and GitHub (Mar 12, 2025); both responded that users are responsible for reviewing AI-generated code. Malicious instructions survived project forking, so downstream dependencies and end users were also exposed.
Classification
- Agent
- GitHub Copilot
- Failure mode
- Security Vulnerability
- Root cause
- Instruction Misunderstanding
- Domain
- Backend
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.