A new attack called Ghostcommit was revealed by researchers at the University of Missouri-Kansas City on July 11, 2026, showing how malicious instructions hidden inside image (PNG) files can trick modern AI coding agents into stealing secrets directly from the victim’s repository. The Ghostcommit attack exploits a structural blind spot in automated and human code reviewers: no one opens the image files when inspecting a pull request, while AI agents read them later and faithfully execute any instructions they find inside them.

Researchers Sudipta Chattopadhyay and Murali Ediga from the university's ASSET research group, along with a proof-of-concept published on GitHub, document in a BleepingComputer that the Ghostcommit attack works on real, widely used software engineering tools such as Cursor, Antigravity, and in combination with Claude Sonnet, Claude Opus, Gemini, and GPT-5.5 models. In one of the demonstrations, Cursor with Claude Sonnet executed the attack on the first try, writing the entire contents of the .env file as an array of 311 integers into legitimate-looking source code.
How the Ghostcommit attack works
The Ghostcommit attack trick relies on an innovative combination of two tools that have become standard in the modern AI-assisted programming workflow. The first is AGENTS.md, a coding conventions file that AI coding agents automatically read and treat as official project policy. The second is a PNG image placed in a documentation folder, with malicious instruction text visible within the image itself but invisible to any text-based reviewer.
The attacker submits a pull request that looks completely innocent: AGENTS.md reads like a normal build and doesn't mention any secrets or sensitive processes. It simply points to an image, e.g. docs/images/build-spec.png. The human reviewer sees a text MD file that looks reasonable and an image that won't open in a text editor anyway. The bot reviewer has binary checking disabled by default.
The real payload is hidden within the PNG: plain-readable text instructions telling the AI agent to read the .env byte by byte, encode each byte as an integer, and emit it as a module constant in new code it will write later. Although the researchers filled the PNG with the phrase “malicious prompt injection” and an explicit command to read the .env, CodeRabbit passed it cleanly, and Bugbot returned zero findings.
See also: HalluSquatting: New attack tricks AI coding assistants into installing malicious code
The time of the theft
The most insidious element of the Ghostcommit attack is that the theft doesn’t happen at the time of the merge — it happens much later, in an unrelated work session. The malicious AGENTS.md remains “dormant” in the repository. At some point, days or weeks later, a project developer asks the AI agent for something completely routine, like a token tracking module or a logging helper.

The agent, as always, reads AGENTS.md at startup, follows the pointer to the image, “reads” it, opens the .env, and writes the requested module with a “provenance” fixed near the top of the file. The developer sees exactly what he asked for and commits — having just published the entire contents of the project’s credentials to a public repository. The attacker, who is monitoring the repo, simply decodes the numbers and has full access to API keys, database credentials, tokens.
Classic secret scanners don’t detect the theft because they don’t convert Python tuples of integers back to ASCII to check what’s hidden. The code looks like a legitimate array of numeric constants in a module. In a study of 6,480 pull requests in the 300 most active public repositories over the past 90 days, the researchers found that 73% of merged PRs made it to the default branch without any meaningful human review — a statistic that translates the gap into a real, massive attack surface.
Tooling counts, not the model
The most illuminating finding of the research is not about the models, but about the tools that “wrap” them. In 10 tests per tool-model combination, Cursor and Antigravity followed the pattern and leaked the .env under Sonnet, Gemini, and GPT-5.5. Claude Code , running the same Sonnet weights, read the same contract and refused, explicitly explaining its refusal, and refused every model the researchers tested.
In Antigravity, Claude Opus wrote the secret but then recognized the social-engineering pattern and deleted it before it was finished. Same model, opposite results, determined by the harness that surrounds it. The editorial team of SecNews points out that this asymmetry highlights a structural weakness of the current AI coding industry: security is not a property of the model but of the system as a whole. The same LLM can be perfectly secure in one product and completely exposed in another.
See also: GhostApproval: Symlink vulnerabilities in 6 AI coding assistants
Old technique, new blind spot
The idea of a hidden instruction within an image is not entirely new. In 2025, Kikimora Morozova and Suha Sabi Hussain of Trail of Bits presented a more sophisticated version: images that appear clean at full resolution but reveal readable prompt injection text when the AI system’s downscaling pipeline resamples them — a method that fooled the Gemini CLI. More recently, the macOS malware Gaslight embedded fake system error messages into its binary, targeting AI-assisted malware analysis tools to interrupt their own analysis.
The Ghostcommit attack does not use any such obfuscation trick. The exfiltration instructions are in plain text within the PNG. What makes it successful is not a hidden signal, but a process weakness: the reviewer does not even open the.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

How to protect yourself from Ghostcommit
The SecNews technical team suggests five practical defense measures. First, every PR that includes image files should be checked with a multimodal reviewer — the researchers themselves presented in their study a GitHub app that opens images and scans them with LLM pass, running on a 4 GB graphics card. In a test against 80 unknown PRs, only one attack passed.
Second, runtime observability: monitoring what the agent is actually doing at the moment it is doing it. If it reads credentials for no apparent reason, the event should be raised, regardless of how we got there. Third, limiting tool permissions: no coding agent should be able to read .env without explicit, per-session authorization from the user.
Fourth, segregation of secrets from the agent's working directory. If the credentials are in a separate vault, secret manager, or runtime-injected env variable, the agent cannot simply "read" them even if the attack requests it. Fifth, mandatory examination of AGENTS.md, .cursorrules, .aiderrules, and all corresponding configuration files in each PR as credential-sensitive: just as we check for changes in the Dockerfile or CI configs, we must also check for changes in the agent policy files.
See also: Friendly Fire: AI agents are tricked into executing malicious code
Ghostcommit highlights the same big truth that previous attacks like HalluSquatting, GhostApproval, and Friendly Fire have shown: the security of agentic AI applications is not a matter of a better model. It is a matter of a better architecture — a sandbox for every dangerous action, a permission model for every sensitive file access, and systematic inspection of every input that reaches the model, even when that input is in the form of an “innocent” documentation image. Without these checks, every new combination of tool and model adds another potential leak to the software supply chain.
