Attacker hijacked an AI coding assistant session to spread the Shai-Hulud worm
What happened
Mandiant's AI Risk and Resilience report described an attacker who compromised a developer's active AI coding assistant session, had it recommend a poisoned package, then used the session to deploy the self-propagating Shai-Hulud worm across about 100 internal repositories, stealing GitHub OAuth tokens, repository secrets and source code.
In the case study, an attacker who had compromised a SaaS provider gained access to a developer's live AI coding assistant session at a software development organization. Acting as a trusted interpreter, the assistant recommended installing an external package, which the developer accepted. The attacker used the session to install an infostealer via a poisoned PyPI package, harvest GitHub OAuth tokens, and spread the Shai-Hulud worm across roughly 100 internal repositories, which automated theft of repository secrets and source code. The attacker then poisoned a package in the organization's own namespace, causing a second infection when another employee pulled it.
How it happened
Manipulated AI: Agent hijack. Malware or poisoned configuration took control of AI tools already installed on the victim's machine and turned them against the victim.
Sources do not say whose AI model was involved. The product type was coding assistant.
Impact
Data was exposed. Data involved: credentials and source code. The impact was confined to one organization and its users or customers.
Severity is rated High, calculated from how far the incident reached and how sensitive the data was.
Was the AI at fault?
No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.
Status and timeline
Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.
It became public in Sep 2026.
Mandiant recommended verifying AI-recommended dependencies against checksums and allowlists, isolating local credentials so extensions cannot read raw tokens, and routing dependency traffic through controlled internal repositories.