Ghostcommit Attack Hides Prompts in PNGs to Bypass AI Code Review
Researchers unveiled Ghostcommit, a supply chain attack that splits malicious instructions and hides them within PNG files. This exploits AI code reviewers' inability to parse images, allowing malicious prompts to bypass security checks.
2026-07-13 ~ 2026-07-14 · 2 related posts
- Hidden Image Instructions Hack Code Agents — sunychoudhary · 2026-07-13
- Malicious PNGs Can Bypass AI Code Reviews — gastao_s_s · 2026-07-14