loader image
ASSET lab researcher points to monitor showing Ghostcommit Hides Prompts; laptop displays leaked .env, GitHub logo visible.
Ghostcommit Hides Prompts in PNGs Exposing Secrets

A novel cybersecurity threat, known as the Ghostcommit attack, hides prompts within PNG images, skillfully evading AI code reviewers. Researchers from ASSET Research Group demonstrated how these malicious prompts cause coding agents to leak sensitive information like .env files without detection. The attack involves splitting the payload, using an innocuous AGENTS.md file to direct the coding agent toward an image housing the malicious code. Text-based reviewers, including CodeRabbit, overlook PNG files, allowing the exploit to go unnoticed.

When developers engage coding agents for unrelated functions, the hidden prompts activate, revealing data through a cleverly encoded integer tuple format. Remarkably, tools such as Cursor and Claude Sonnet have fallen prey to this tactic, while others, like Claude Code, resist. Researchers now propose a multimodal GitHub review app that offers promising detection capabilities. Cybersecurity professionals should further investigate these findings to safeguard themselves against this evolving threat. For full details, visit the official news article at the link below.

New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents

Write a Reply or Comment

Your email address will not be published. Required fields are marked *