Open source bytes.
osbytes is a collective of builders contributing to open source for the common good.
Contribution activity
last 365 days · org-wideRecent activity
0 eventsFeatured projects
all repos →Latest from the blog
archive →Ghostcommit hides prompt injection in a PNG and walks past AI pull request review
ASSET Research Group showed a merged AGENTS.md can point at a PNG whose rendered text orders a coding agent to read .env and emit it as integer tuples. Text reviewers never open the image; secret scanners do not decode tuples back to ASCII.
2026-07-11
@osbytesAI-assisted7 min read#ai · #prompt-injection · #github · #security · #supply-chain · #ci-cd · #credentialsjscrambler 8.14.0 shipped a preinstall hook with a Rust infostealer and no matching git tag
The official jscrambler npm package published 8.14.0 today with a preinstall script that drops a platform-matched Rust binary from a fake dist/intro.js container. No commit or tag exists for 8.14.0 in the public GitHub repo; 8.14.0 is still installable from npm.
2026-07-11
@osbytesAI-assisted8 min read#npm · #supply-chain · #security · #javascript · #ci-cd · #credentials · #incident-responseGitLost: a crafted public issue can leak private repos through GitHub Agentic Workflows
Noma Labs showed that a public issue body can steer a GitHub Agentic Workflow with org-wide read access into posting private README contents as a public comment. No stolen token required; the dangerous bit is the workflow config.
2026-07-07
@osbytesAI-assisted6 min read#github · #github-actions · #ai · #security · #prompt-injection · #automation · #supply-chain