Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant reported that an attacker hijacked an active AI coding assistant session at an unnamed SaaS provider. The assistant recommended malware, which was accepted, after which the Shai-Hulud worm spread to about 100 internal repositories and stole secrets and source code.
- Attack began with hijacking active AI assistant session
- Assistant suggested malware, and it was accepted
- Shai-Hulud worm infected about 100 internal repositories
- Repository secrets and source code were stolen
Read next
Security