What happened
A malicious GitHub Issue contained a hidden prompt injection payload. When an AI assistant with a GitHub MCP connection read the issue, it was hijacked and directed to exfiltrate private repository names and salary data, writing them into public pull request bodies.