Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-17 Β· updated: 2026-09-17 Β· tags: [incident, global] Β· confidence: high Β· severity: high Β· affected_sectors: [global] Β· au_impact: true

Mandiant's September 2026 report describes an intrusion at an unnamed software-as-a-service provider in which an attacker hijacked an active AI coding-assistant session and then spread the Shai-Hulud worm across approximately 100 internal code repositories. The sequence is the analytically important part, because the first compromise was not technical: the coding assistant recommended software that the attacker had poisoned, and the developer accepted the recommendation. Having entered through the developer's own live session β€” the report does not say how that session was taken over β€” the attacker installed an infostealer via a poisoned PyPI package and stole GitHub OAuth tokens, then deployed the self-propagating worm across the internal repositories, stealing repository secrets and source code for the company's products. The attacker also poisoned a package inside the company's official namespace, and a second employee who pulled the compromised version caused a further infection β€” the same dependency-confusion shape that has defined the Shai-Hulud family's reach. Mandiant's recommendations for AI-assisted development map one-to-one onto what failed: check AI-recommended third-party dependencies against cryptographic checksums and approved allowlists; keep raw API keys and long-lived OAuth tokens "out of direct reach of extensions"; and route dependency traffic through controlled internal repositories rather than public package sources. The case sits in a documented progression β€” Mandiant's March 2026 report said attackers had moved during 2025 from using generative AI mainly to speed up their own work to using large language models inside malware and active attacks. The wider Shai-Hulud family has hit developer tooling repeatedly this year: a Keyv-linked npm worm poisoned hundreds of packages in August and planted hooks for Claude Code and Visual Studio Code, and a later variant was found scanning 469 locations for credentials across developer systems, CI/CD tooling, cloud configuration and AI tool files. Mandiant states the available evidence does not link those campaigns to this intrusion.

Attribute Detail
Sector Global (Macro)
Date 2026-09-17
Source The Hacker News
Reliability Tier 2