logo

Ghostcommit attack hides malicious AI instructions in images

ID: 16f164af-7a1d-5e80-b45e-c7eee1315b77

STIX ID: report--16f164af-7a1d-5e80-b45e-c7eee1315b77

Feed Name: Malwarebytes Blog

Threat Score
35/100

Date Published: 2026-07-13

Date Updated: 2026-07-16

...
...

Ghostcommit is a proof-of-concept showing that AI coding assistants can be manipulated by hidden instructions embedded in images referenced from repository files, enabling agents to read and exfiltrate secrets if the development toolchain or harness trusts those inputs; researchers demonstrated varied behavior across different tooling, highlighted the supply-chain/agent-security nature of the risk, and recommended restricting secrets, inspecting non-text attachments, and monitoring AI agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.