Case · DiggingBeagle record

Hijacked AI coding-assistant session became the entry path for Shai-Hulud across about 100 repositories

Mandiant investigated an intrusion at an unnamed SaaS provider where an attacker hijacked a developer's active AI coding-assistant session. After an attacker-poisoned package was recommended and accepted, the chain led to an infostealer, stolen GitHub OAuth tokens, Shai-Hulud across roughly 100 internal repositories, repository-secret theft and source-code exfiltration.

Incident-response findings published by Mandiant. The victim SaaS provider, AI coding-assistant product, attacker identity, exact incident date and session-hijack mechanism are not identified in the cited public material.

Case kind
incident
Claims
5

Reconstruction

Claims & evidence

reported findingsupported

After acceptance, Mandiant says the attacker used the active session to install an infostealer through a poisoned PyPI package, harvest GitHub OAuth tokens and deploy Shai-Hulud across approximately 100 internal code repositories.

reported findingsupported

The attacker then poisoned a package inside the organization's official namespace, and another employee pulling the compromised version caused a secondary downstream infection.

reported findingsupported

Mandiant says the Shai-Hulud worm automated theft of repository secrets and programmatic exfiltration of proprietary product source code.

reported findingsupported

Mandiant says a threat actor compromised an unnamed SaaS provider and hijacked an active AI coding-assistant session on a developer workstation.

reported findingsupported

The hijacked assistant recommended installation of an external software package poisoned by the attacker; after the recommendation was accepted, the assistant's trusted workflow facilitated malicious software installation.

Implications

What remains unknown

  • The affected SaaS provider is not publicly identified in the cited material.
  • The AI coding-assistant product is not publicly identified in the cited material.
  • The threat actor is not publicly attributed in the cited material.
  • The exact incident date is not stated in the cited public case study.
  • The method used to hijack the active assistant session is not disclosed.
  • The complete quantity of stolen repository secrets and proprietary source code is not stated.
  • The cited material does not establish whether additional downstream organizations were infected.

Cite this record

DiggingBeagle. “Hijacked AI coding-assistant session became the entry path for Shai-Hulud across about 100 repositories.” https://diggingbeagle.com/cases/hijacked-ai-coding-assistant-session-became-the-entry-path-for-shai-hulud-across/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.