Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Cybersecurity · September 17, 2026

Cybersecurity·thehackernews.com

Mandiant reports that attackers took over a live AI coding-assistant session inside an unnamed SaaS company and used it to plant the Shai-Hulud worm across roughly 100 internal repositories. The intrusion began when the compromised assistant suggested a poisoned software package that a developer accepted, giving the attacker a way to spread further. From there, the worm went on to steal repository secrets and source code, highlighting the danger of trusting AI coding suggestions without verification.

// source: thehackernews.com ↗

Back to Blog