Source · DiggingBeagle record
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
Independent BleepingComputer report published July 11, 2026. It reconstructs the split-image attack, CodeRabbit/Bugbot blind spot, fake provenance cover, 311-integer synthetic .env output, harness-dependent results and ASSET's multimodal defensive reviewer, and notes that the researchers disclosed findings to affected vendors.
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Independent BleepingComputer report published July 11, 2026. It reconstructs the split-image attack, CodeRabbit/Bugbot blind spot, fake provenance cover, 311-integer synthetic .env output, harness-dependent results and ASSET's multimodal defensive reviewer, and notes that the researchers disclosed findings to affected vendors.
Claim-level citations (3)
- supportsGhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code: ASSET reports surveying 6,480 pull requests across the 300 most active public repositories over the preceding 90 days; in that sample, 73% of merged pull requests reached the default branch without substantive human review and without bot review.
Section 'How Ghostcommit works', paragraph reporting the 6,480-PR survey and 73% figure
- supportsGhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code: In the researchers' tested pull request, CodeRabbit's default configuration excluded PNG files and Cursor Bugbot returned no findings against the image-based payload, even though the image explicitly contained the secret-access instructions.
Section 'How Ghostcommit works', paragraphs describing CodeRabbit and Bugbot behavior
- supportsGhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code: ASSET reports that its multimodal pull-request defender, which inspects convention text and images as separate inputs, detected 49 of 50 attacks in a live trial of 80 previously unseen pull requests, including every image-channel variant, while flagging none of the 30 benign pull requests.
Final defensive-reviewer paragraphs reporting 49/50 attacks and zero false alarms on 30 legitimate PRs
Cite this record
DiggingBeagle. “'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets.” https://diggingbeagle.com/sources/ghostcommit-hides-prompt-injection-in-images-to-fool-ai-agents-steal-secrets/
Citation guidance