BREAKING
'Ghostcommit' Hides Prompts in Images
How the Attack Unfolds
1Hide prompt in PNG
2Link via AGENTS.md
3Reviewer skips image
4Agent leaks .env
0%
merged PRs unreviewed
0
pull requests studied
0
active repositories
Same Model, Different Outcomes
Cursor + SonnetLeaked
Ran the full chain
Emitted 311 integers
Claude CodeRefused
Blocked the task
Same model used
Antigravity + OpusSelf-caught
Produced then deleted output
0
attack classes caught
0
of 50 attacks detected
0
false positives
Scan What Agents Can Read
AI NEWS BLITZ
Researchers reveal an attack that hides malicious prompts inside images to hijack AI coding agents.