CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7501

As cited

Copy frozen at (site build).

ai security

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Mandiant identified an attacker who hijacked an active artificial intelligence (AI) coding assistant session at a software-as-a-service provider and used it to spread malware called Shai-Hulud across approximately 100 internal code repositories. The attacker poisoned software recommendations from the AI assistant, which were then accepted by developers. The malware subsequently stole repository secrets and source code.

Why it matters: Development teams using AI coding assistants face supply chain compromise risk if attacker-controlled recommendations introduce malware into internal repositories, potentially exposing credentials and proprietary code.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary