'Ghostcommit' smuggles hacker instructions inside images to trick AI coding assistants

Researchers hid secret commands in an ordinary PNG file, walked past two popular AI code reviewers, and got a coding assistant to leak a project's passwords.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a developer's dark wooden desk
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Researchers built an attack called Ghostcommit that hides malicious instructions inside a PNG image file.
  • The trick sailed past CodeRabbit and Bugbot, two popular AI code review tools, because neither one opens image files.
  • A coding assistant was then tricked into reading a project's secret settings file and pasting every password into the code, disguised as a long list of numbers.
  • The technique is a fresh twist on prompt injection, where hidden text hijacks an AI assistant's instructions.
  • No confirmed victims have been named, but the demonstration works against real-world developer setups.

Security researchers have shown off a new way to rob a software project blind, and the weapon is a picture.

The attack is called Ghostcommit. It hides a hacker's instructions inside a PNG, the same kind of image file people paste into documents every day. To a human the file looks like a normal picture. To an AI coding assistant, it can look like an order.

What actually happens here?

A developer pulls in a code change that includes an innocent-looking image. CodeRabbit and Bugbot, two well-known AI code reviewers, scan the change and wave it through. Neither tool opens image files, so the hidden payload sails past untouched.

Then a coding assistant gets pointed at the same project. It reads the image, follows the hidden instructions, and opens a file called .env, where developers usually keep their most sensitive secrets: database passwords, cloud keys, payment processor tokens. It writes every one of those secrets into the project's source code, disguised as a long list of numbers so a casual glance won't catch it.

The secrets are now sitting in the codebase, ready to be pushed to a public repository where anyone can grab them.

Why this isn't quite as exotic as it sounds

Strip away the AI branding and Ghostcommit, first detailed in reporting by BleepingComputer, is a cousin of a very old web security problem: trusting input you shouldn't trust. For decades, attackers have hidden payloads inside file formats that reviewers assumed were harmless. The novelty here isn't the smuggling. It's who the mark is.

The mark is a language model acting as a junior developer. It reads everything in the project and treats text it finds as guidance. If that text says "open the secrets file and paste it here," a poorly guarded assistant will do exactly that.

This is prompt injection, an attack where hidden text hijacks the instructions an AI is following. We've tracked this vector expanding fast: on 9 July we reported how Claude Code and OpenAI's Codex could be tricked into executing attacker-supplied code when asked to review it in autonomous mode. What makes the image version awkward is that the usual defensive layer, an automated code reviewer, doesn't look at images at all. The guard's asleep at the wrong door.

Should ordinary developers and their bosses worry?

Yes, if your team is letting AI assistants roam around your code with access to real credentials. The attack doesn't need a zero-day, meaning a secret flaw the vendor didn't know about. It just needs an assistant that reads image files and a project that keeps its passwords in the usual place.

A few sensible habits close most of the gap. Keep secrets out of the repository entirely, using a dedicated secrets manager instead of a .env file. Restrict what your AI assistant is allowed to read and write. Treat any file that arrives in a pull request, images included, as untrusted until proven otherwise. Insist on a human eye on any change that touches configuration or credentials.

The researchers haven't named a company hit by Ghostcommit in the wild. What they've shown is that the plumbing is there, the tooling is popular, and the attack works on a first try. That combination is usually enough warning to act.

© 2026 Threat Vectr