Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
AI-summarised brief · reviewed before publication
Mandiant reported that an attacker hijacked an active AI coding‑assistant session at an unnamed SaaS provider, then used the session to install an infostealer via a poisoned PyPI package. The attacker stole repository secrets, source code, and GitHub OAuth tokens, and subsequently deployed the Shai‑Hulud worm to spread across roughly 100 internal code repositories. The worm also poisoned a package in the company’s official namespace, leading to a second infection when another employee pulled the compromised version. The incident is detailed in Mandiant’s September 2026 report, which recommends three controls for AI‑assisted development.
💡 Why It Matters
- · The attack demonstrates how AI assistants can become a vector for sophisticated malware that harvests credentials and code, underscoring the need for tighter controls on AI‑driven development workflows.