GhostCommit Hides AI Attack in Images
Researchers from the ASSET Research Group have unveiled GhostCommit, a proof-of-concept attack that demonstrates how AI coding assistants can be manipulated through hidden instructions embedded inside image files. The research highlights a growing security risk as AI-powered code review tools become increasingly common in software development.
The attack works by concealing malicious instructions within a seemingly harmless PNG image and referencing it through an AGENTS.md configuration file. During a routine pull request, the image appears innocuous to human reviewers, who are unlikely to inspect its hidden content. However, AI coding assistants can interpret the embedded instructions and execute them during subsequent development tasks.
In the researchers' demonstration, the compromised AI agent followed the hidden commands, accessed sensitive files, and secretly inserted extracted information into source code using obfuscated techniques. This created a covert channel for data theft that could evade both manual code reviews and many automated security scanners.
A key finding of the study is that the AI harness—the software layer controlling the model—plays a greater role in security than the language model itself. Tools such as Cursor and Antigravity allo
The research underscores a new class of multimodal prompt-injection attacks, where hidden content inside images influences AI behavior. As organizations increasingly rely on AI-assisted software development, experts warn that repositories, images, configuration files, and AI workflows must all be treated as potential attack surfaces. Strengthening AI guardrails, validating external assets, and implementing secure review processes will be critical to preventing similar supply-chain attacks in the future.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




