Malicious Instructions Hidden in Images Trick AI Assistants Into Leaking Project Secrets
As companies increasingly integrate AI assistants into development workflows, the security of source-code reviews has come under scrutiny. A new attack called “GhostCommit” hides malicious instructions in innocuous PNG files, bypassing conventional text scanning. When a multimodal AI assistant reads the image, it can be tricked into accessing and exfiltrating sensitive keys and credentials from a project. The vulnerability exposes blind spots in current AI tools’ multimodal review and access controls.
The ASSET research team at the University of Missouri–Kansas City disclosed the technique on July 11, 2026. Its analysis of 6,480 pull requests across 300 active repositories found that as much as 73% of merged code reached default branches without substantive human or bot review, creating fertile ground for GhostCommit. The research has prompted the industry to reassess open-source software supply-chain security and call for multimodal image-security scanning.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →