Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Learn about AI in HR at Disrupt 2026

    September 17, 2026

    Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

    September 17, 2026

    The Fed rate decision is shaping up to be a nightmare for Warsh. Bitcoin might still shine

    September 17, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Learn about AI in HR at Disrupt 2026
    • Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
    • The Fed rate decision is shaping up to be a nightmare for Warsh. Bitcoin might still shine
    • Irrigation’s climate benefit could equal 363 years of its own emissions
    • ‘A good way to die’: triumph and tragedy among dispersing African wild dogs
    • Chart of the Week: Amazon’s lobbying operation dwarfs the other Emmy winners’ K Street spending • OpenSecrets
    • EU Chief Floats Making Canada the Bloc’s First Associate Member
    • ‘Pretend I’m on the ticket’: Trump hits campaign trail in bid to boost Republican hopes | Donald Trump
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 17
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 17, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 16, 2026Artificial Intelligence / Software Security

    Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories.

    Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the company’s products.

    The case appears in Mandiant’s September 2026 report. The public case study does not say when the intrusion happened or how the attacker took over the active coding-assistant session.

    How the Attack Unfolded

    After the recommendation was accepted, the attacker used the developer’s active session to install an infostealer through a poisoned PyPI package. The attacker also stole GitHub OAuth tokens.

    The attacker then deployed the self-spreading Shai-Hulud worm across approximately 100 internal code repositories.

    Cybersecurity

    The attacker also poisoned a package in the company’s official namespace. Another employee pulled the compromised version, causing a second infection.

    Mandiant had already documented attackers using AI in real attacks. In a March 2026 report, it said attackers had moved during 2025 from using generative AI mainly to speed up work to using large language models in malware and active attacks.

    How Defenders Can Protect AI-Assisted Development

    For this case, Mandiant recommends three controls for AI-assisted development:

    • Check AI-recommended third-party dependencies against cryptographic checksums and approved allowlists.
    • Keep raw API keys, long-lived OAuth tokens, and other secrets out of direct reach of extensions.
    • Route dependency traffic through controlled internal repositories.

    Recent Shai-Hulud-family attacks have also targeted developer tools and credentials. In August, a Keyv-linked npm worm poisoned hundreds of packages and planted hooks for Claude Code and Visual Studio Code, while a later analysis found a Shai-Hulud variant scanning 469 locations for credentials across developer systems, CI/CD tools, cloud configurations, and AI tool files.

    These were separate campaigns, and the available evidence does not link them to the unnamed Mandiant intrusion.

    Assistant attacker Coding Hijacks Repositories Session ShaiHulud spreads
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Webinar: What happens in the first hours of a Google Workspace breach

    AI made software development unrecognizable. Is cybersecurity next?

    Anthropic wants Claude to analyze your bank account and financial data

    Spain’s data agency gets first report of AI-powered data breach

    Finding Hope During Tough Tech Times

    Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Learn about AI in HR at Disrupt 2026

    September 17, 2026

    Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

    September 17, 2026

    The Fed rate decision is shaping up to be a nightmare for Warsh. Bitcoin might still shine

    September 17, 2026

    Irrigation’s climate benefit could equal 363 years of its own emissions

    September 17, 2026
    Latest Posts

    What is Trump Media’s Truth API and why is it controversial?

    August 4, 2026

    How ProPublica Tested Hundreds of Omaha Homes for Lead — ProPublica

    August 4, 2026

    Golar LNG raises $600 million loan with FLNG business expansion in mind

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Learn about AI in HR at Disrupt 2026

    September 17, 2026

    Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

    September 17, 2026

    The Fed rate decision is shaping up to be a nightmare for Warsh. Bitcoin might still shine

    September 17, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.