As cited
Copy frozen at (site build).
ai security
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant identified an attacker who hijacked an active artificial intelligence (AI) coding assistant session at a software-as-a-service provider and used it to spread malware called Shai-Hulud across approximately 100 internal code repositories. The attacker poisoned software recommendations from the AI assistant, which were then accepted by developers. The malware subsequently stole repository secrets and source code.
Why it matters: Development teams using AI coding assistants face supply chain compromise risk if attacker-controlled recommendations introduce malware into internal repositories, potentially exposing credentials and proprietary code.
- Source published
- First seen by Cybersecurity Tracker