{"slug": "attacker-hijacks-ai-coding-assistant-session-spreads-shai-hulud-across-about-100", "title": "Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories", "summary": "Mandiant reported that an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and spread the Shai-Hulud worm across roughly 100 internal code repositories, stealing repository secrets and product source code. The assistant recommended attacker-poisoned software that was accepted, after which the attacker installed an infostealer via a poisoned PyPI package and stole GitHub OAuth tokens; a poisoned package in the company's official namespace caused a second infection when another employee pulled it. The case appears in Mandiant's September 2026 AI risk and resilience report, which recommends verifying AI-recommended dependencies against cryptographic checksums and allowlists, keeping API keys and long-lived OAuth tokens out of extension reach, and routing dependency traffic through controlled internal repositories.", "body_md": "Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread [Shai-Hulud](https://thehackernews.com/2025/09/40-npm-packages-compromised-in-supply.html) across about 100 internal code repositories.\n\nBefore the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the company’s products.\n\nThe case appears in [Mandiant’s September 2026 report](https://cloud.google.com/security/resources/ai-risk-and-resilience-2026). The public case study does not say when the intrusion happened or how the attacker took over the active coding-assistant session.\n\n### How the Attack Unfolded\n\nAfter the recommendation was accepted, the attacker used the developer’s active session to install an infostealer through a poisoned PyPI package. The attacker also stole GitHub OAuth tokens.\n\nThe attacker then deployed the self-spreading Shai-Hulud worm across approximately 100 internal code repositories.\n\nThe attacker also poisoned a package in the company’s official namespace. Another employee pulled the compromised version, causing a second infection.\n\nMandiant had already documented attackers using AI in real attacks. In a [March 2026 report](https://cloud.google.com/security/resources/ai-risk-and-resilience), it said attackers had moved during 2025 from using generative AI mainly to speed up work to using large language models in malware and active attacks.\n\n### How Defenders Can Protect AI-Assisted Development\n\nFor this case, Mandiant recommends three controls for AI-assisted development:\n\n- Check AI-recommended third-party dependencies against cryptographic checksums and approved allowlists.\n- Keep raw API keys, long-lived OAuth tokens, and other secrets out of direct reach of extensions.\n- Route dependency traffic through controlled internal repositories.\n\nRecent Shai-Hulud-family attacks have also targeted developer tools and credentials. In August, a [Keyv-linked npm worm](https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html) poisoned hundreds of packages and planted hooks for Claude Code and Visual Studio Code, while a later analysis found a Shai-Hulud variant scanning [469 locations for credentials](https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html) across developer systems, CI/CD tools, cloud configurations, and AI tool files.\n\nThese were separate campaigns, and the available evidence does not link them to the unnamed Mandiant intrusion.", "url": "https://wpnews.pro/news/attacker-hijacks-ai-coding-assistant-session-spreads-shai-hulud-across-about-100", "canonical_source": "https://www.swapupdate.in/attacker-hijacks-ai-coding-assistant-session-spreads-shai-hulud-across-about-100-repositories/", "published_at": "2026-09-17 10:13:58+00:00", "updated_at": "2026-09-17 10:53:36.195669+00:00", "lang": "en", "topics": ["ai-safety", "ai-tools", "ai-agents", "developer-tools", "artificial-intelligence"], "entities": ["Mandiant", "Shai-Hulud", "GitHub", "PyPI", "Claude Code", "Visual Studio Code", "Keyv"], "alternates": {"html": "https://wpnews.pro/news/attacker-hijacks-ai-coding-assistant-session-spreads-shai-hulud-across-about-100", "markdown": "https://wpnews.pro/news/attacker-hijacks-ai-coding-assistant-session-spreads-shai-hulud-across-about-100.md", "text": "https://wpnews.pro/news/attacker-hijacks-ai-coding-assistant-session-spreads-shai-hulud-across-about-100.txt", "jsonld": "https://wpnews.pro/news/attacker-hijacks-ai-coding-assistant-session-spreads-shai-hulud-across-about-100.jsonld"}}