
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
Researchers discovered a sneaky technique called 'Ghostcommit' that hides malicious instructions inside image files to trick AI coding assistants into stealing sensitive information, like passwords and secret keys, from software projects. Because these AI tools don't inspect image files for hidden commands, they can be manipulated without anyone noticing. If you or your business uses AI-powered code review tools, be aware that they may not be fully secure and could be fooled into exposing private data.
































