An attacker hijacked an AI coding assistant to spread a worm
Assessment
Mandiant confirms an attacker took over a developer's active AI coding-assistant session and that the assistant recommended attacker-poisoned software, which the developer accepted — leading to an infostealer installed via a poisoned PyPI package, GitHub OAuth token theft, and the Shai-Hulud worm spreading across about 100 internal repositories. But Mandiant's public case study explicitly does not say how the attacker took over the active session, and the documented AI role was recommending a poisoned dependency that a human accepted — a human-in-the-loop supply-chain acceptance, not a demonstrated compromise of the AI model or the assistant software itself. Framing this as 'the AI assistant was hacked' overstates what Mandiant disclosed; the mechanism of the session takeover remains unknown, and the more precise description is a poisoned AI-recommended dependency that a developer approved.
Where this claim appeared
Mandiant (via The Hacker News) · 2026-09-16
https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.htmlWhat “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
Shai-Hulud via a hijacked AI coding-assistant session: Mandiant's case of a poisoned recommendation that spread a wormThink this assessment is wrong? Report an error.