Attacker Compromises AI Coding Assistant, Spreads Shai-Hulud Worm to 100 Repositories

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Mandiant has reported that an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider, subsequently spreading the Shai-Hulud worm across approximately 100 internal code repositories. This incident highlights the vulnerabilities associated with AI-assisted development tools.

According to Mandiant’s September 2026 report, the attacker initially poisoned software recommended by the AI assistant, which was then accepted by the developer. This led to the theft of repository secrets and source code for the company’s products. The report does not specify when the intrusion occurred or how the attacker gained control of the coding-assistant session.

Details of the Attack

After the compromised recommendation was accepted, the attacker utilized the developer’s active session to install an infostealer via a poisoned PyPI package. Additionally, GitHub OAuth tokens were stolen, allowing the attacker to deploy the self-spreading Shai-Hulud worm across the internal repositories.

The attacker also poisoned a package within the company’s official namespace, leading to a second infection when another employee inadvertently pulled the compromised version. Mandiant has previously documented the use of AI in cyberattacks, noting a shift in 2025 from using generative AI for efficiency to employing large language models in active attacks.

Recommendations for Protection

To mitigate risks associated with AI-assisted development, Mandiant recommends implementing the following controls:

  • Verify AI-recommended third-party dependencies against cryptographic checksums and approved allowlists.
  • Ensure that raw API keys, long-lived OAuth tokens, and other sensitive information are not easily accessible to extensions.
  • Route dependency traffic through controlled internal repositories.

Recent attacks linked to the Shai-Hulud family have also targeted developer tools and credentials. In August, a related Keyv-linked npm worm compromised hundreds of packages, while a later analysis revealed a Shai-Hulud variant scanning for credentials across various developer systems and tools.

These incidents underscore the evolving threat landscape and the need for robust security measures in software development environments.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Norwegian Authorities Investigate Telenor for Alleged Complicity in Myanmar Junta’s Crimes Against Humanity

Law enforcement agencies in Norway are investigating telecommunications giant Telenor for potential complicity in crimes against humanity linked to its operations with Myanmar's military...

Ransomware Incidents Surge in the Gulf, Targeting Businesses Amid Increased Cyber Threats

Ransomware incidents in the Gulf region have surged dramatically, with organized criminal groups increasingly targeting businesses in sectors where disruption can compel victims to...

Palo Alto Networks Develops Behavioral Clustering Model for Cloud Identity Security

Mapping Cloud Identities: A New Approach to Security As organizations increasingly migrate to cloud environments, the complexity of managing identities—human, machine, and autonomous agents—has become...

Red Hat releases important security update for gstreamer1-plugins-bad-free on RHEL 8.4

Red Hat has announced an important security update for gstreamer1-plugins-bad-free, specifically targeting users of Red Hat Enterprise Linux (RHEL) 8.4. This update is applicable...