Modern development workflows increasingly rely on AI-driven Code Assistants to accelerate software delivery and improve code quality. However, recent research has highlighted a powerful new threat: hackers can exploit these tools to introduce backdoors and create malicious content without immediate detection.
See also: New 'NotDoor' backdoor targets Outlook users

This vulnerability manifests itself through misuse of content attachment features, where contaminated external data sources feed malicious prompts directly into the Code Assistant workflow. As a result, developers may inadvertently embed hidden payloads into their codebases, undermining security and trust.
The attack surface is widened when malicious users compromise public repositories, documentation sites, or data feeds, embedding load instructions that look like legitimate code comments or metadata. When these infected sources are attached as content to an IDE plugin or via a remote URL, Code Assistant treats the malicious snippets as part of the developer's request.
Palo Alto Networks researchers identified this indirect prompt injection channel as a critical vulnerability that bypasses standard content moderation filters and code review safeguards. In a simulated scenario, a set of social media posts provided as CSV input caused the assistant to generate code that contained a hidden backdoor. The malicious function, named fetch_additional_data , connected to a C2 server controlled by the attacker and executed returned commands under the guise of additional analytics. When developers accepted the generated prompt, the hidden routine was automatically executed, providing unauthorized remote access .
See also: Researchers warn about the MystRodX Backdoor

The simplicity of the exploit relies on the inability of Code Assistant to distinguish between instructions intended by the user and those secretly embedded in external data. This backdoor functionality introduced by the compromised assistant is retrieved from a remote C2 server. In practice, the introduced code is seamlessly integrated into legitimate workflows, avoiding occasional inspection.
Developers accustomed to trusting AI-generated suggestions may overlook subtle differences in function signatures or comments. Additionally, Code Assistants support multiple programming languages, meaning attackers don’t need to tailor payloads to a specific environment—the assistant adapts the backdoor to the linguistic content of the project.
The infection mechanism begins with malicious users seeding a public data source—such as a README on GitHub or a publicly indexed CSV—with instructions disguised as legitimate code comments. Upon import, Code Assistant parses the content in its prompt, adding the malicious instructions before the user’s query. This placement ensures that the backdoor code appears as a natural extension of the developer’s request. Once the assistant generates the combined result, the hidden routine is executed on the developer’s computer once the code is implemented.
See also: UK: Drops order for backdoor in Apple iCloud

Detection evasion comes from the backdoor’s minimal footprint: no external libraries beyond standard HTTP requests, generic function names, and obfuscated C2 URLs. By embedding the routine within expected analytics functions, the exploit avoids raising alarms during manual or automated code reviews. As AI tools become more autonomous, this channel will require strict content validation and strict execution controls to prevent undetected compromise.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
