ThreatPaper
Unverified

The Mandiant intrusion is part of the wider Shai-Hulud npm-worm campaign

Assessment

The Mandiant case involved the Shai-Hulud self-spreading worm, and separate Shai-Hulud-family campaigns drew wide coverage in the same window — an August Keyv-linked npm worm that poisoned hundreds of packages and planted hooks for Claude Code and Visual Studio Code, and a variant analyzed as scanning 469 locations for credentials across developer systems, CI/CD tooling, cloud configuration and AI tool files. But The Hacker News, reporting Mandiant's finding, states plainly that 'these were separate campaigns, and the available evidence does not link them to the unnamed Mandiant intrusion.' Because 'Shai-Hulud' now spans multiple distinct operations, a reader could easily assume the Mandiant SaaS-provider intrusion is the same event as the npm-registry worm campaigns; on the current evidence, that link is not established.

Where this claim appeared

The Hacker News · 2026-09-16

https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

Shai-Hulud via a hijacked AI coding-assistant session: Mandiant's case of a poisoned recommendation that spread a worm

Think this assessment is wrong? Report an error.