Start with Identity
News

A hijacked AI coding assistant session spread Shai-Hulud to about 100 internal repositories

Mandiant describes an intrusion at an unnamed SaaS provider where a poisoned package, recommended through a developer's AI coding assistant session, led to stolen GitHub OAuth tokens and the Shai-Hulud worm in roughly 100 internal repositories.

By SWI Community TeamSep 16, 2026

Mandiant's September 2026 AI risk report describes an intrusion at an unnamed software-as-a-service provider that started inside a developer's AI coding assistant session. The assistant recommended software the attacker had poisoned, and the developer accepted it. The attacker then used that active session to install an infostealer through a poisoned PyPI package, took the developer's GitHub OAuth tokens, and deployed the self-spreading Shai-Hulud worm across about 100 internal code repositories. A second infection followed when the attacker poisoned a package in the company's own official namespace and another employee pulled it. Mandiant does not say how the session was first taken over. Its three recommended controls: verify AI-recommended dependencies against checksums and allowlists, keep secrets away from editor extensions, and route dependency traffic through controlled repositories.

Why it matters

The assistant is not the identity that got abused here; the developer is. Everything the attacker did ran on credentials the developer's machine already held, and the GitHub OAuth tokens on that machine were broad enough to seed a hundred repositories and publish into the company's trusted namespace. That is the control to check first: what a single workstation token can push, and whether publishing to an internal package namespace needs anything more than a token that happens to be on a laptop.

The AI angle matters in a narrower way than the headline suggests. An assistant's suggestion arrives with borrowed authority, and developers accept it faster than they would a random package from a search. Treat dependencies the assistant proposes exactly like dependencies a stranger proposes, which is Mandiant's first control, and keep the developer's tokens short-lived and scoped so that the next accepted suggestion cannot reach this far. See secrets in repositories and CI and agent instruction injection.

Source: The Hacker News

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.