Hijacked AI coding-assistant session became the entry path for Shai-Hulud across about 100 repositories
Mandiant investigated an intrusion at an unnamed SaaS provider where an attacker hijacked a developer's active AI coding-assistant session. After an attacker-poisoned package was recommended and accepted, the chain led to an infostealer, stolen GitHub OAuth tokens, Shai-Hulud across roughly 100 internal repositories, repository-secret theft and source-code exfiltration.
Incident-response findings published by Mandiant. The victim SaaS provider, AI coding-assistant product, attacker identity, exact incident date and session-hijack mechanism are not identified in the cited public material.
Case kind
incident
Claims
5
Reconstruction
Claims & evidence
reported findingsupported
After acceptance, Mandiant says the attacker used the active session to install an infostealer through a poisoned PyPI package, harvest GitHub OAuth tokens and deploy Shai-Hulud across approximately 100 internal code repositories.
Locator: Case study 1, paragraph beginning 'Once the recommendation was accepted'
reported findingsupported
The attacker then poisoned a package inside the organization's official namespace, and another employee pulling the compromised version caused a secondary downstream infection.
Locator: Case study 1, paragraph beginning 'Mandiant investigated a sophisticated intrusion'
reported findingsupported
The hijacked assistant recommended installation of an external software package poisoned by the attacker; after the recommendation was accepted, the assistant's trusted workflow facilitated malicious software installation.
DiggingBeagle. “Hijacked AI coding-assistant session became the entry path for Shai-Hulud across about 100 repositories.” https://diggingbeagle.com/cases/hijacked-ai-coding-assistant-session-became-the-entry-path-for-shai-hulud-across/
DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.
We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.