Sev0

AI security incidents, tracked

All incidents / Manipulated AI

Attacker hijacked an AI coding assistant session to spread the Shai-Hulud worm

Undisclosed software development organization, disclosed Sep 2026 Manipulated AI Data exposed High

What happened

Mandiant's AI Risk and Resilience report described an attacker who compromised a developer's active AI coding assistant session, had it recommend a poisoned package, then used the session to deploy the self-propagating Shai-Hulud worm across about 100 internal repositories, stealing GitHub OAuth tokens, repository secrets and source code.

In the case study, an attacker who had compromised a SaaS provider gained access to a developer's live AI coding assistant session at a software development organization. Acting as a trusted interpreter, the assistant recommended installing an external package, which the developer accepted. The attacker used the session to install an infostealer via a poisoned PyPI package, harvest GitHub OAuth tokens, and spread the Shai-Hulud worm across roughly 100 internal repositories, which automated theft of repository secrets and source code. The attacker then poisoned a package in the organization's own namespace, causing a second infection when another employee pulled it.

How it happened

Manipulated AI: Agent hijack. Malware or poisoned configuration took control of AI tools already installed on the victim's machine and turned them against the victim.

Sources do not say whose AI model was involved. The product type was coding assistant.

Impact

Data was exposed. Data involved: credentials and source code. The impact was confined to one organization and its users or customers.

Severity is rated High, calculated from how far the incident reached and how sensitive the data was.

Was the AI at fault?

No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.

Status and timeline

Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.

It became public in Sep 2026.

Mandiant recommended verifying AI-recommended dependencies against checksums and allowlists, isolating local credentials so extensions cannot read raw tokens, and routing dependency traffic through controlled internal repositories.

Sources

  1. https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html
  2. https://cloud.google.com/security/resources/ai-risk-and-resilience-2026

Related incidents

Cite as: Sev0, "Attacker hijacked an AI coding assistant session to spread the Shai-Hulud worm", https://sev0.fyi/incidents/2026-09-01-mandiant-shai-hulud-ai-coding-assistant/. Data for this record: incidents.json.