The record
Written from the 1 report below. Nothing here is unsourced.
- An attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and spread the self-spreading Shai-Hulud worm across about 100 internal code repositories.
- The coding assistant had recommended a poisoned software package, the recommendation was accepted, and the attacker used the developer's active session to install an infostealer and steal GitHub OAuth tokens.
- The worm stole repository secrets and source code for the company's products, and a poisoned package in the company's official namespace caused a second infection when another employee pulled it.
- The case appears in Mandiant's September 2026 report, which does not say when the intrusion happened or how the attacker took over the active coding-assistant session.
- The case matters because it shows attackers using AI-assisted development tools themselves as an entry point into company codebases and secrets.
What to watch next
- Whether Mandiant later discloses when the intrusion happened and how the AI coding-assistant session was hijacked.
- Whether companies adopt Mandiant's three recommended controls, including checksum verification of AI-recommended dependencies and keeping secrets out of extension reach.
- Whether new Shai-Hulud-family attacks continue targeting developer tools, credentials, and AI tool files.
Coverage1
1 report
English national1
All filed from India
Named India · Claude Code · GitHub · PyPI · Visual Studio Code · Mandiant · Shai-Hulud
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
