Check Point Research disclosed a now-remediated covert channel that allowed separate ChatGPT code-execution containers to exchange data despite account and network isolation. The flaw involved a shared internal JFrog Artifactory service: its Item Management API allowed containers to read and modify mutable metadata on cached repository items, effectively turning package metadata into a bidirectional cross-account communication channel.
An attacker could deliver hidden instructions through a malicious prompt, shared conversation, or custom GPT, causing a victim’s ChatGPT session to execute concealed tasks alongside a benign visible request. In Check Point’s proof of concept, the session accessed data from a connected Gmail account and relayed it to the attacker while returning an innocuous response. OpenAI confirmed the affected internal Artifactory instance had been decommissioned before the report was completed.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Check Point demonstrated that a malicious prompt, shared conversation, or custom GPT could invisibly direct a victim's ChatGPT session to access connected Gmail data and relay it through the Artifactory-based covert channel. The victim received an innocuous visible response and only a post-action Gmail label.
In June 2026, Check Point Research identified a bidirectional covert channel between separate ChatGPT code-execution containers. Containers could use mutable properties on shared internal JFrog Artifactory repository items to exchange data despite network isolation.
Check Point stated that it had previously reported a separate ChatGPT data-exfiltration channel based on DNS lookups. According to Check Point, OpenAI fixed that issue on February 20.
After Check Point disclosed the issue, OpenAI confirmed that the internal JFrog Artifactory instance used for the cross-account channel had been decommissioned by completion of the report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
7 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcecryptika.com
Open sourcethehackernews.com
Open sourcemalware.news
Open sourceresearch.checkpoint.com
Open sourcedocs.jfrog.com
Open sourcehelp.openai.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.