Mandiant found an attacker who hijacked an active ai coding-assistant session, had it recommend…
mandiant found an attacker who hijacked an active ai coding-assistant session, had it recommend poisoned packages, stole github oauth tokens, and spread a worm across about 100 internal repos. the assistant didn't fail — it was operated.
the trust boundary is now the session, not the developer's machine.
Context
The Hacker News, 16 September 2026, reports Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. The assistant recommended software the attacker had poisoned and the recommendation was accepted, an infostealer was installed through a poisoned PyPI package, GitHub OAuth tokens were stolen, and a package in the company's official namespace was also poisoned. The coverage quotes that the public case study does not say when the intrusion happened or how the attacker took over the session.
The incident details are second-hand from outlets describing Mandiant's report. The victim is unnamed, and the date and hijack method are not published. Mandiant's own wording was not located in the report text read, so details such as about 100 and the OAuth tokens are secondary-supported. The assistant did not fail, it was operated is the author's interpretation.
Related work
Watch next
- The case-study passage in Mandiant's report.
Sources
- Attacker hijacks AI coding assistant (The Hacker News, 16 Sep 2026)thehackernews.com
- AI Risk and Resilience Report 2026 (Google Cloud)cloud.google.com
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 18 September 2026 at 14:34 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →