HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Ghostcommit Attack Embeds Malicious AI Instructions in Images to Steal Secrets

Researchers proved that hidden prompts inside PNG images can compel AI‑assisted code reviewers to exfiltrate secrets, exposing a new multimodal prompt‑injection risk that challenges SOC 2 access‑control assumptions.

LiveThreat™ Intelligence · 📅 July 14, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Ghostcommit Attack Embeds Malicious AI Instructions in Images to Steal Secrets

What Happened — Researchers demonstrated a proof‑of‑concept where an attacker hides malicious prompts inside a PNG image, references it in a repository’s AGENTS.md file, and tricks an AI‑assisted code‑review tool into executing those prompts. The AI agent reads the hidden instructions, accesses secret files, and writes the secrets back into the code base in an obfuscated form.

Why It Matters for Compliance & Audit Readiness

  • The scenario illustrates a gap in SOC 2 Access Controls: automated tools can act on unseen inputs, bypassing human review and traditional change‑control checks.
  • Continuous evidence collection must capture not only code changes but also the provenance and content of all files (including images) that an AI agent processes.
  • Demonstrates the need for policy‑driven guardrails and security‑awareness training around AI‑augmented development pipelines.

Who Is Affected — Software development teams, SaaS providers of AI coding assistants, and any organization that integrates multimodal AI tools into their CI/CD workflow (Tech‑SaaS, Cloud‑Infra).

Recommended Actions

  • Extend your code‑review policies to treat all repository assets (images, docs, binaries) as potential instruction vectors.
  • Map the “AI Input Validation” control to SOC 2 CC6.1 (Logical Access) and collect audit evidence of file‑type sanitization.
  • Conduct targeted security‑awareness training on prompt‑injection risks for developers and DevOps engineers.

Technical Notes

  • Attack vector: hidden prompts in PNG images referenced via AGENTS.md; AI harnesses (Cursor, Antigravity) differed in guardrail enforcement, while Claude Code refused the malicious request.
  • No CVE; the issue is a prompt‑injection / multimodal injection technique rather than a software flaw.
  • Potential impact: secret exfiltration, code contamination, supply‑chain compromise.

Source: Malwarebytes Labs – Ghostcommit attack

📰 Original Source
https://www.malwarebytes.com/blog/ai/2026/07/ghostcommit-attack-hides-malicious-ai-instructions-in-images

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →