AI Weekly Malaysia

Back to items Summaries

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

ID
25087
Status
summarized
Published
16 Sep 2026, 9:37 PM
Fetched
16 Sep 2026, 10:36 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
8.5
Created
16 Sep 2026, 10:36 PM
Tags
Audience
developersvibe_codersai_agent_userssaas_founders

What happened

Mandiant reports an attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider, got the assistant to recommend a poisoned PyPI package, and spread the Shai-Hulud worm across roughly 100 internal repositories, stealing secrets and source code. A second infection occurred after the attacker poisoned a package in the company's own namespace and another employee pulled it. Mandiant recommends verifying AI-recommended dependencies against checksums and allowlists, keeping secrets out of extension reach, and routing dependency traffic through controlled internal repositories.

Why it matters

If you use AI coding assistants (Copilot, Claude Code, Cursor, etc.), you need to treat their package recommendations as untrusted input — verify against checksums and allowlists before installing. This incident shows the attack chain is real: a poisoned PyPI package recommended by the assistant led to stolen GitHub OAuth tokens and worm propagation across 100 repos. Route dependency installs through controlled internal mirrors rather than pulling directly from public registries, and keep long-lived tokens and API keys out of reach of editor extensions.

Discussion angle

What's your current process when an AI coding assistant suggests a third-party package — do you verify it at all, and would routing installs through an internal mirror be feasible for your team?

Top