Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

The Hacker News by The Hacker News
September 16, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalSep 16, 2026Artificial Intelligence / Software Security

Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories.

Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the company’s products.

The case appears in Mandiant’s September 2026 report. The public case study does not say when the intrusion happened or how the attacker took over the active coding-assistant session.

How the Attack Unfolded

After the recommendation was accepted, the attacker used the developer’s active session to install an infostealer through a poisoned PyPI package. The attacker also stole GitHub OAuth tokens.

The attacker then deployed the self-spreading Shai-Hulud worm across approximately 100 internal code repositories.

The attacker also poisoned a package in the company’s official namespace. Another employee pulled the compromised version, causing a second infection.

Mandiant had already documented attackers using AI in real attacks. In a March 2026 report, it said attackers had moved during 2025 from using generative AI mainly to speed up work to using large language models in malware and active attacks.

How Defenders Can Protect AI-Assisted Development

For this case, Mandiant recommends three controls for AI-assisted development:

  • Check AI-recommended third-party dependencies against cryptographic checksums and approved allowlists.
  • Keep raw API keys, long-lived OAuth tokens, and other secrets out of direct reach of extensions.
  • Route dependency traffic through controlled internal repositories.

Recent Shai-Hulud-family attacks have also targeted developer tools and credentials. In August, a Keyv-linked npm worm poisoned hundreds of packages and planted hooks for Claude Code and Visual Studio Code, while a later analysis found a Shai-Hulud variant scanning 469 locations for credentials across developer systems, CI/CD tools, cloud configurations, and AI tool files.

These were separate campaigns, and the available evidence does not link them to the unnamed Mandiant intrusion.



Source link

The Hacker News

The Hacker News

Next Post

SDMC Showcases Deployable AI Home Services at IBC 2026

Recommended.

How Intel Got Caught Off Guard By A CPU Shortage Again

How Intel Got Caught Off Guard By A CPU Shortage Again

January 28, 2026
OpenAI Models Escaped Containment and Hacked Hugging Face

OpenAI Models Escaped Containment and Hacked Hugging Face

July 21, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

April 2, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio