Incident
Published 2026-09-16
Verified 2026-09-19

Mandiant: attacker hijacks AI coding-assistant session, spreads Shai-Hulud across ~100 repos

Mandiant AI Risk and Resilience Report 2026 (Google Cloud; wired by The Hacker News 16 September) case study: after compromising a SaaS provider, an attacker hijacked an active AI coding-assistant session on a developer workstation. The assistant recommended a poisoned external package; once accepted, the attacker used the session to install an infostealer via a poisoned PyPI package, harvest GitHub OAuth tokens, and deploy the self-propagating Shai-Hulud worm across about 100 internal repositories (secret theft and programmatic exfiltration). Distinct from earlier Keyv-linked npm worm / Mini Shai-Hulud supply-chain desk notes. Defenders: treat AI assistant tool-install prompts as high-risk; constrain package installs; rotate GitHub tokens; audit recent repo automation. Primary: Mandiant/Google Cloud report.

Product
AI coding assistants; developer workstations; GitHub / PyPI supply chain
Exploited in Australia?
unknown
Patch to
Revoke exposed GitHub OAuth/tokens; remove Shai-Hulud artefacts; constrain AI assistant install capabilities; rebuild from known-good

Primary: Mandiant AI Risk and Resilience Report 2026 (Google Cloud) · Vendor: Google Cloud / Mandiant · The Hacker News — Shai-Hulud AI session (16 Sep 2026)

ai cloud identity