logo

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

ID: 76d91ad7-915b-5994-8008-b0555a6d4250

STIX ID: report--76d91ad7-915b-5994-8008-b0555a6d4250

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2026-07-11

Date Updated: 2026-07-19

Author: Ax Sharma

...
...

Researchers from the ASSET Research Group demonstrated a proof-of-concept called 'Ghostcommit' where malicious instructions embedded as readable text inside a PNG referenced by an AGENTS.md file bypass human and bot review; coding agents that follow the convention later read the image, open a repository's .env, encode its bytes as integer constants, and insert them into commits, enabling secret exfiltration. The report highlights a structural blind spot in PR review tooling (many PRs merge with little review), shows tests across multiple agent/tool combinations, and proposes defenses including a multimodal pull-request app that inspects images and runtime monitoring of agent behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.