BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AI Coding Assistant Hijacked to Spread Shai-Hulud Worm in 100 Repos

Attacker hijacks active AI coding session to deploy Shai-Hulud worm, steals secrets from 100 repos

  • A hacker hijacked an active AI coding-assistant session at a SaaS firm to deploy the self-spreading Shai-Hulud worm.
  • The worm stole secrets and source code from roughly 100 internal repositories after the assistant recommended poisoned software.
  • Mandiant recommends checking dependencies against checksums, limiting token exposure, and routing traffic through controlled repositories.

A previously unknown attacker hijacked an active AI coding-assistant session at a software-as-a-service provider, later deploying the self-spreading Shai-Hulud worm across approximately 100 internal code repositories, according to Mandiant‘s September 2026 report. The intrusion, detailed in the cloud security firm’s public case study, began when the AI assistant recommended software that the attacker had poisoned, and the recommendation was accepted. Consequently, the worm stole repository secrets and the source code for the company’s products.

- Advertisement -

After the recommendation was accepted, the attacker used the developer’s active session to install an infostealer through a poisoned PyPI package. The attacker also stole GitHub OAuth tokens, then deployed the Shai-Hulud worm across the internal repositories. Meanwhile, the attacker poisoned a package in the company’s official namespace, and another employee pulled the compromised version, causing a second infection.

The public case study does not specify when the intrusion occurred or how the attacker seized control of the active coding-assistant session. However, Mandiant had already documented attackers using AI in real attacks, noting in a March 2026 report that attackers moved during 2025 from using generative AI mainly to speed up work to employing large language models in malware and active attacks. For defense, Mandiant recommends three controls for AI-assisted development: checking AI-recommended third-party dependencies against cryptographic checksums and approved allowlists, keeping raw API keys and long-lived OAuth tokens out of direct reach of extensions, and routing dependency traffic through controlled internal repositories.

Recent Shai-Hulud-family attacks have also targeted developer tools and credentials, with an August campaign poisoning hundreds of npm packages and implanting hooks for Claude Code and Visual Studio Code. A later analysis found a Shai-Hulud variant scanning 469 locations for credentials across developer systems, CI/CD tools, cloud configurations, and AI tool files. These were separate campaigns, and the available evidence does not link them to the unnamed Mandiant intrusion.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Kalshi gold markets double Ether fees in September

Gold 15-minute contracts on Kalshi generated $5 million in estimated fees in September, nearly...

ARK Invest Buys $16.2M in Archer and Joby Shares

Ark Invest bought 2.57 million Archer Aviation shares for $11.9 million and 753,330 Joby...

Bitcoin Group SE seeks alternative after BaFin denies MiCA

BaFin refused futurum bank AG’s application for authorization as a crypto-asset service provider under...

Google launches Nano Banana 2.1 AI with better accuracy, half price

Google released Nano Banana 2.1 on Oct. 6, rolling it out across the Gemini...

Justin Sun admits Poloniex is his personal exchange

Justin Sun admitted that his exchange Poloniex is used solely by himself, implying wash...

Must Read

How to Set Up a Simple Bitcoin Tip Jar for Your Site or Stream

QUICK LINKSWhat a tip jar is, in plain wordsWhat you needBuild a payment link that just worksAdd a QR code that actually scansWhere to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading