news.mlab.sh
Back to the feed
threat-intel

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

High
Summary

A sophisticated attacker exploited an AI coding assistant to spread the Shai-Hulud worm across approximately 100 internal code repositories, stealing secrets and source code. The incident highlights a growing trend of attackers leveraging AI tools for malicious purposes, including spreading malware and stealing credentials.

A sophisticated attacker successfully hijacked an active AI coding assistant session at an unnamed software-as-a-service provider, leading to the widespread deployment of the Shai-Hulud worm. The incident, detailed in Mandiant’s September 2026 report, involved the attacker recommending malicious software that was subsequently accepted by the developer. The worm then stole repository secrets and source code for the company’s products, demonstrating a dangerous escalation of AI-assisted attacks.

Following the initial compromise, the attacker utilized the hijacked developer session to install a poisoned PyPI package, effectively gaining access to the system. Simultaneously, the attacker stole GitHub OAuth tokens, further expanding their reach and ability to move laterally within the organization’s infrastructure. The Shai-Hulud worm subsequently propagated across roughly 100 internal code repositories, indicating a significant breach of security.

Adding to the complexity, the attacker also poisoned a package within the company’s official namespace, and another employee unwittingly pulled the compromised version, resulting in a second infection. Mandiant has previously documented attackers utilizing AI in active attacks, noting a shift from using generative AI to speed up work to leveraging large language models for malware and active attacks since March 2026.

Recent Shai-Hulud-family attacks have also targeted developer tools and credentials. In August, a Keyv-linked npm worm poisoned hundreds of packages and planted hooks for Claude Code and Visual Studio Code, while a later analysis found a Shai-Hulud variant scanning 469 locations for credentials across developer systems, CI/CD tools, cloud configurations, and AI tool files. These attacks were separate campaigns, and the available evidence does not currently link them to the Mandiant intrusion.

Read the full article at The Hacker News