importantSYS.SOURCE: The Hacker News• 2026-09-16T19:07:07+05:30
AI Coding Assistant Session Compromised, Leading to Shai-Hulud Worm Spread in 100 Repositories
An attacker hijacked an AI coding assistant session, deploying the Shai-Hulud worm across 100 internal repositories by poisoning dependencies. The incident underscores risks in AI-assisted development and highlights the need for stricter dependency verification and secret management.
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories.
Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the
*** END OF TRANSMISSION ***