AnalysisCybersecuritySeptember 16, 2026

Mandiant: hijacked AI coding assistant session spread Shai-Hulud worm

An attacker took over an active AI coding-assistant session at an unnamed SaaS provider, got the assistant's poisoned software recommendation accepted, then spread the Shai-Hulud worm across about 100 internal repositories. The worm stole repository secrets and product source code; a poisoned package in the company's official namespace caused a second infection.

1 source

More stories today

Open the live feed
Mandiant: hijacked AI coding assistant session spread Shai-Hulud worm