A hijacked AI coding assistant session spread Shai-Hulud to about 100 internal repositories
Mandiant describes an intrusion at an unnamed SaaS provider where a poisoned package, recommended through a developer's AI coding assistant session, led to stolen GitHub OAuth tokens and the Shai-Hulud worm in roughly 100 internal repositories.
Mandiant's September 2026 AI risk report describes an intrusion at an unnamed software-as-a-service provider that started inside a developer's AI coding assistant session. The assistant recommended software the attacker had poisoned, and the developer accepted it. The attacker then used that active session to install an infostealer through a poisoned PyPI package, took the developer's GitHub OAuth tokens, and deployed the self-spreading Shai-Hulud worm across about 100 internal code repositories. A second infection followed when the attacker poisoned a package in the company's own official namespace and another employee pulled it. Mandiant does not say how the session was first taken over. Its three recommended controls: verify AI-recommended dependencies against checksums and allowlists, keep secrets away from editor extensions, and route dependency traffic through controlled repositories.
Why it matters
The assistant is not the identity that got abused here; the developer is. Everything the attacker did ran on credentials the developer's machine already held, and the GitHub OAuth tokens on that machine were broad enough to seed a hundred repositories and publish into the company's trusted namespace. That is the control to check first: what a single workstation token can push, and whether publishing to an internal package namespace needs anything more than a token that happens to be on a laptop.
The AI angle matters in a narrower way than the headline suggests. An assistant's suggestion arrives with borrowed authority, and developers accept it faster than they would a random package from a search. Treat dependencies the assistant proposes exactly like dependencies a stranger proposes, which is Mandiant's first control, and keep the developer's tokens short-lived and scoped so that the next accepted suggestion cannot reach this far. See secrets in repositories and CI and agent instruction injection.
Source: The Hacker News
Related on Start with Identity
- BlogCrowdSec kept a departing engineer's GitHub access open, and lost 170 private repositories through it
An engineer's laptop was infected in the May TanStack npm attack. Eleven days later his still-active GitHub OAuth token was used to copy about 170 of CrowdSec's
- BlogGitLab's incoming email address is a non-expiring token that commits code and runs CI as you
Aikido Security showed that the personal address GitLab issues for creating issues by email can also open merge requests that GitLab commits in your name and ca
- BlogOkta found 1,843 unexpired AI session tokens sitting in a single infostealer dump
Okta analysed a 7GB infostealer dump from 5,871 machines and found 44,791 JWTs, 1,843 of them still unexpired on release day, plus 24 live API keys for Gemini,
- CVECitrix Bleed, session-token leak from NetScaler ADC
A buffer over-read on NetScaler ADC/Gateway leaked session tokens in the clear. Attackers replayed them and skipped the login, including MFA. CISA KEV. October
- GlossaryDevice Bound Session Credentials (DBSC)
Device Bound Session Credentials (DBSC) is a web standard that binds a browser session to a private key held in the device's hardware, so a session cookie stole
- BreachInfostealers and session hijacking: stealing the session, skipping the login
Infostealer malware has made stolen session cookies a primary attack path, letting attackers ride an authenticated session and skip both the password and MFA en