The ai coding assistant became the attacker's delivery vehicle. mandiant's september report…
the ai coding assistant became the attacker's delivery vehicle. mandiant's september report describes a hijacked assistant session that recommended a poisoned package, and once a dev accepted it, a worm spread across about 100 internal repos stealing oauth tokens and source.
the recommendation layer is now the attack surface.
Context
Mandiant's AI Risk and Resilience Report 2026, dated September 2026, describes a case where an actor compromised a SaaS provider and hijacked an active AI coding assistant session on a developer workstation. The assistant recommended a poisoned external package, and once it was accepted the actor installed an infostealer through a poisoned PyPI package, harvested GitHub OAuth tokens and deployed the Shai-Hulud worm across approximately 100 internal repositories, stealing repository secrets and source code. A later poisoned package in the organization's namespace caused a downstream infection.
This is one case study in the report, the SaaS provider is unnamed and no attribution was read. The tokens stolen were GitHub OAuth tokens, and the repository count is approximate. The report frames the assistant as a trusted interpreter exploited through a hijacked session, not a model flaw. This entry adds Mandiant's own text to the earlier note, which used secondary coverage.
Related work
- Earlier note on the same case ↗Same Mandiant case.
Watch next
- Whether the provider is named and any Mandiant follow-up.
Sources
- AI Risk and Resilience Report 2026 (Mandiant, Google Cloud)cloud.google.com
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 20 September 2026 at 01:34 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →