Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Attacker hijacks AI coding assistant session, spreads Shai-Hulud worm across 100 internal repositories.
Intelligence analysis by Qwen 2.5 (3B)

Mandiant reports an attacker hijacks an AI coding assistant session and spreads a worm across 100 internal repositories, stealing secrets and source code.
An attacker used a coding assistant to trick a developer into installing a bad program, which then spread to many places in the company's code. The attacker stole secrets and copied code.
Analysis
{"heading_1":"The Attack Unfolds","paragraph_1":"The case underscores the need for robust security controls in AI-assisted development and highlights the evolving threat landscape.","paragraph_2":"Defenders should continue to monitor and adapt to new AI-based threats, such as those targeting developer tools and credentials.","paragraph_3":"Mandiant recommends controls to protect AI-assisted development, such as checking AI-recommended dependencies and keeping secrets out of extensions.","heading_2":"Previous AI Attacks","heading_3":"Future of AI in Security"}
Key points
- Attacker hijacks AI coding assistant session
- Spreads Shai-Hulud worm across 100 repositories
- Stole secrets and copied code
- Mandiant recommends controls for AI-assisted development
- Previous attacks have moved from speed-up work to active attacks
Future AI tools can be designed to better detect and prevent such attacks.
Attacks like this will likely become more common as AI is used more in development.



