# A hijacked AI coding assistant session spread Shai-Hulud to about 100 internal repositories

Source: https://startwithidentity.com/blog/2026-09-16-hijacked-ai-coding-assistant-session-spread-shai-hulud-to-100-repos/
Last updated: 2026-09-16
License: content by Start with Identity. Cite the source URL.

---

Mandiant's September 2026 AI risk report describes an intrusion at an unnamed software-as-a-service provider that started inside a developer's AI coding assistant session. The assistant recommended software the attacker had poisoned, and the developer accepted it. The attacker then used that active session to install an infostealer through a poisoned PyPI package, took the developer's GitHub OAuth tokens, and deployed the self-spreading [Shai-Hulud worm](https://startwithidentity.com/blog/2026-09-03-shai-hulud-worm-now-hunts-469-credential-locations/) across about 100 internal code repositories. A second infection followed when the attacker poisoned a package in the company's own official namespace and another employee pulled it. Mandiant does not say how the session was first taken over. Its three recommended controls: verify AI-recommended dependencies against checksums and allowlists, keep secrets away from editor extensions, and route dependency traffic through controlled repositories.

## Why it matters

The assistant is not the identity that got abused here; the developer is. Everything the attacker did ran on credentials the developer's machine already held, and the GitHub OAuth tokens on that machine were broad enough to seed a hundred repositories and publish into the company's trusted namespace. That is the control to check first: what a single workstation token can push, and whether publishing to an internal package namespace needs anything more than a token that happens to be on a laptop.

The AI angle matters in a narrower way than the headline suggests. An assistant's suggestion arrives with borrowed authority, and developers accept it faster than they would a random package from a search. Treat dependencies the assistant proposes exactly like dependencies a stranger proposes, which is Mandiant's first control, and keep the developer's tokens short-lived and scoped so that the next accepted suggestion cannot reach this far. See [secrets in repositories and CI](https://startwithidentity.com/techniques/secrets-in-repositories-and-ci/) and [agent instruction injection](https://startwithidentity.com/techniques/agent-instruction-injection/).

Source: [The Hacker News](https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html)
