Ghostcommit exposes the image blind spot in AI code review

ASSET Research Group's proof-of-concept hides a secret-stealing instruction inside a PNG that text-based reviewers skip.

By · Published

Primary source: BleepingComputer

Why it matters

Ghostcommit turns a common AI coding workflow into a supply-chain risk: the PR looks clean because the instruction lives in a file reviewers skip, while the leak happens later during normal agent work.

Illustration of ASSET Research Group's Ghostcommit proof-of-concept: an AI code-review window showing a PNG file that conceals a secret-stealing instruction.

ASSET Research Group and Sudipta Chattopadhyay published a proof-of-concept this week showing how a malicious pull request can hide a prompt-injection instruction inside a PNG, pass AI code review, and later induce a coding agent to leak a repository's .env secrets into source code.…

Reader comments

Conversation for this story loads after sign-in.