HomeSecurityHacker attack on AI coding assistant session spreads Shai-Hulud

Hacker attack on AI coding assistant session spreads Shai-Hulud

Mandiant -as-a-service (SaaS) provider. The attacker managed to hijack an active session of an artificial intelligence (AI)-based coding assistant and then spread the Shai-Hulud malware to approximately 100 of the company’s internal code repositories.

See also: Vulnerabilities in npm and yarn platforms allow bypass of Shai-Hulud defenses

Article Image: Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

This attack, detailed in Mandiant's September 2026 report, highlights the growing risks associated with the use of AI in software development.

Before the malware was distributed to the repositories, the AI ​​assistant suggested software that had been poisoned by the attacker. This suggestion was accepted by the developer, which allowed the attacker to install an infostealer via a poisoned PyPI package. This infostealer was designed to steal repository secrets and source code, giving the attacker access to critical information about the company's products.

Mandiant’s report doesn’t specify when exactly the breach occurred or how the attacker managed to take over the coding assistant’s active session. However, it is clear that after accepting the poisoned software offer, the attacker exploited the developer’s active session to proceed with the attack. In addition, the attacker was able to steal GitHub OAuth tokens, further strengthening his access to the company’s systems.

Shai-Hulud, a self-propagating worm, was then deployed to approximately 100 internal code repositories. This worm is known for its ability to spread rapidly and cause severe damage to systems and data. In addition, the attacker poisoned a package in the company's official namespace, which was then downloaded by another employee, causing a second infection.

See also: New version of Shai-Hulud worm spreads via npm, GitHub

Shai-Hulud - SecNews.gr

The use of artificial intelligence in cybersecurity attacks is nothing new. Mandiant had already documented cases where attackers used AI in real-world attacks. In a March 2026 report, it noted that attackers had shifted during 2025 from using genetic AI primarily to speed up work to using large language models in malware and active attacks.

To address these types of threats, Mandiant recommends three key controls for AI-assisted development. First, third-party dependencies suggested by AI should be checked against cryptographic checksums and approved whitelists. Second, raw API keys, long-lived OAuth tokens, and other secrets should be kept out of direct access by extensions. Third, dependency traffic should be routed through controlled internal repositories.

Recent attacks by the Shai-Hulud family have also targeted developer tools and credentials. In August, an npm worm linked to Keyv poisoned hundreds of packages and installed hooks for Claude Code and Visual Studio Code. A later analysis found a variant of Shai-Hulud scanning 469 locations for credentials in developer systems, CI/CD tools, cloud configurations, and AI tool files.

Although these campaigns were separate, the fact that Shai-Hulud is being used in such attacks highlights the severity of the threat.

See also: Shai-Hulud supply chain attack: Over 180 NPM packages affected

WooCommerce Wholesale Lead Capture PHP web shell vulnerability CVE-2026-27540

This case is a strong reminder for companies to strengthen their security practices, especially when using AI in software development. Protecting systems from such attacks requires constant vigilance and the adoption of advanced security measures.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS