Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
- ID
- 25087
- Status
- summarized
- Published
- 16 Sep 2026, 9:37 PM
- Fetched
- 16 Sep 2026, 10:36 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 8.5
- Created
- 16 Sep 2026, 10:36 PM
- Tags
- Audience
- developersvibe_codersai_agent_userssaas_founders
What happened
Mandiant reports an attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider, got the assistant to recommend a poisoned PyPI package, and spread the Shai-Hulud worm across roughly 100 internal repositories, stealing secrets and source code. A second infection occurred after the attacker poisoned a package in the company's own namespace and another employee pulled it. Mandiant recommends verifying AI-recommended dependencies against checksums and allowlists, keeping secrets out of extension reach, and routing dependency traffic through controlled internal repositories.
Why it matters
If you use AI coding assistants (Copilot, Claude Code, Cursor, etc.), you need to treat their package recommendations as untrusted input — verify against checksums and allowlists before installing. This incident shows the attack chain is real: a poisoned PyPI package recommended by the assistant led to stolen GitHub OAuth tokens and worm propagation across 100 repos. Route dependency installs through controlled internal mirrors rather than pulling directly from public registries, and keep long-lived tokens and API keys out of reach of editor extensions.
Discussion angle
What's your current process when an AI coding assistant suggests a third-party package — do you verify it at all, and would routing installs through an internal mirror be feasible for your team?