← Founder Notes
Archive

Mandiant found an attacker who hijacked an active ai coding-assistant session, had it recommend…

Yethikrishna ROriginal on Threads

mandiant found an attacker who hijacked an active ai coding-assistant session, had it recommend poisoned packages, stole github oauth tokens, and spread a worm across about 100 internal repos. the assistant didn't fail — it was operated.

the trust boundary is now the session, not the developer's machine.

Context

The Hacker News, 16 September 2026, reports Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. The assistant recommended software the attacker had poisoned and the recommendation was accepted, an infostealer was installed through a poisoned PyPI package, GitHub OAuth tokens were stolen, and a package in the company's official namespace was also poisoned. The coverage quotes that the public case study does not say when the intrusion happened or how the attacker took over the session.

How it compares

The incident details are second-hand from outlets describing Mandiant's report. The victim is unnamed, and the date and hijack method are not published. Mandiant's own wording was not located in the report text read, so details such as about 100 and the OAuth tokens are secondary-supported. The assistant did not fail, it was operated is the author's interpretation.

Related work

Watch next

  • The case-study passage in Mandiant's report.

Sources

  1. Attacker hijacks AI coding assistant (The Hacker News, 16 Sep 2026)thehackernews.com
  2. AI Risk and Resilience Report 2026 (Google Cloud)cloud.google.com

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 18 September 2026 at 14:34 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/mandiant-found-an-attacker-who-hijacked-an-active-DdbEldCkSzu" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="Mandiant found an attacker who hijacked an active ai coding-assistant session, had it recommend…"></iframe>

More notes