Cybersecurity firm Mandiant has disclosed details of an incident where an attacker hijacked an active AI coding assistant session at an unnamed software as a service provider and used it to spread the Shai-Hulud worm across approximately 100 internal code repositories. The incident highlights growing security risks around AI-assisted software development environments, where compromised dependencies, exposed credentials, and trusted developer workflows can create opportunities for large-scale attacks. According to Mandiant, the attacker initially influenced the AI coding assistant to recommend a software package that had already been compromised. After the recommendation was accepted, the attacker used the active development session to introduce malicious code into the environment and later expand access across the company’s repositories.
The attack involved the use of a poisoned PyPI package that installed an infostealer on the targeted system. Through this access, the attacker obtained sensitive information, including repository secrets, source code associated with the company’s products, and GitHub OAuth tokens. The stolen credentials helped enable further movement within the organization’s development environment. Mandiant said the attacker then deployed the Shai-Hulud worm across around 100 internal repositories, allowing the malicious activity to spread through the company’s software development ecosystem. The attacker also compromised a package within the company’s official namespace, which resulted in another employee downloading the affected version and triggering an additional infection path.
The case was included in Mandiant’s September 2026 report on AI risk and resilience, although the publicly available case study did not reveal when the intrusion occurred or provide details about how the attacker gained control of the active AI coding assistant session. Mandiant has previously documented the increasing use of artificial intelligence tools in cyberattacks. In its March 2026 research, the company noted that attackers had shifted from using generative AI primarily for improving efficiency to incorporating large language models into malware development and active attack operations. The latest incident demonstrates how AI-powered development tools can become a security concern when combined with unsafe dependency practices, weak credential management, or insufficient controls around third-party software.
To reduce risks associated with AI-assisted development, Mandiant recommends organizations implement stronger security measures around software dependencies and developer access. The company advises verifying AI-recommended third-party packages through cryptographic checksums and approved allowlists before deployment. It also recommends keeping sensitive credentials, including API keys and long-lived OAuth tokens, away from direct access by extensions and development assistants. Additionally, organizations should route dependency downloads through controlled internal repositories to improve visibility and reduce exposure to compromised packages. Recent Shai-Hulud-related campaigns have also targeted developer environments and credentials. In August, a Keyv-linked npm worm affected hundreds of packages and introduced hooks targeting tools such as Claude Code and Visual Studio Code, while another analysis identified a Shai-Hulud variant scanning 469 locations for credentials across developer systems, CI/CD environments, cloud configurations, and AI tool files. These incidents remain separate campaigns, and current evidence does not connect them with the Mandiant-documented intrusion.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





