- A hacker hijacked an active AI coding-assistant session at a SaaS firm to deploy the self-spreading Shai-Hulud worm.
- The worm stole secrets and source code from roughly 100 internal repositories after the assistant recommended poisoned software.
- Mandiant recommends checking dependencies against checksums, limiting token exposure, and routing traffic through controlled repositories.
A previously unknown attacker hijacked an active AI coding-assistant session at a software-as-a-service provider, later deploying the self-spreading Shai-Hulud worm across approximately 100 internal code repositories, according to Mandiant‘s September 2026 report. The intrusion, detailed in the cloud security firm’s public case study, began when the AI assistant recommended software that the attacker had poisoned, and the recommendation was accepted. Consequently, the worm stole repository secrets and the source code for the company’s products.
After the recommendation was accepted, the attacker used the developer’s active session to install an infostealer through a poisoned PyPI package. The attacker also stole GitHub OAuth tokens, then deployed the Shai-Hulud worm across the internal repositories. Meanwhile, the attacker poisoned a package in the company’s official namespace, and another employee pulled the compromised version, causing a second infection.
The public case study does not specify when the intrusion occurred or how the attacker seized control of the active coding-assistant session. However, Mandiant had already documented attackers using AI in real attacks, noting in a March 2026 report that attackers moved during 2025 from using generative AI mainly to speed up work to employing large language models in malware and active attacks. For defense, Mandiant recommends three controls for AI-assisted development: checking AI-recommended third-party dependencies against cryptographic checksums and approved allowlists, keeping raw API keys and long-lived OAuth tokens out of direct reach of extensions, and routing dependency traffic through controlled internal repositories.
Recent Shai-Hulud-family attacks have also targeted developer tools and credentials, with an August campaign poisoning hundreds of npm packages and implanting hooks for Claude Code and Visual Studio Code. A later analysis found a Shai-Hulud variant scanning 469 locations for credentials across developer systems, CI/CD tools, cloud configurations, and AI tool files. These were separate campaigns, and the available evidence does not link them to the unnamed Mandiant intrusion.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
