bleeping-computer · Crawled Jul 11, 2026
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
3 IoCs
Read original article ↗
AI Summary
The 'Ghostcommit' attack exploits a review gap in AI code review systems by hiding malicious prompt injection instructions within a PNG image referenced in a pull request. The image contains text instructing the AI agent to read and exfiltrate environment variables (.env) by encoding them as integers in a seemingly benign module constant. Since reviewers and automated tools typically do not inspect image content, the malicious payload bypasses detection and is later executed by AI coding agents, leading to secret exfiltration.
AI-extracted · verify before operational use