Attacker hijacks an AI coding session and spreads Shai-Hulud to 100 repositories
Mandiant reported that an attacker hijacked a developer's active AI coding-assistant session at a software company and used it to spread the self-replicating Shai-Hulud worm across about 100 internal code repositories. The chain started when the AI assistant recommended a piece of software the attacker had poisoned, and the developer accepted the suggestion. Using the live session, the attacker installed an infostealer through a poisoned PyPI package and stole GitHub access tokens, then unleashed the worm, which stole repository secrets and source code. The attacker also poisoned a package in the company's own namespace, so a second developer's pull caused a reinfection. It shows AI-recommended dependencies as a new poisoning path.
- Check
- Check dependencies that an AI assistant recommends against cryptographic checksums and an approved allowlist before installing them, and keep API keys and long-lived OAuth tokens out of reach of coding-assistant extensions.
- Affected
- Development teams using AI coding assistants that install dependencies with the developer's credentials; a poisoned recommendation or hijacked session can plant an infostealer, steal tokens, and spread a worm through repositories.
- Fix
- Route dependency traffic through internal repositories, verify AI-suggested packages before use, scope tokens the assistant can reach, monitor for worm-like package activity, and treat a compromised coding session as a supply-chain incident.