The coding assistant session is the new perimeter. mandiant reported september 16 that an attacker…
the coding assistant session is the new perimeter. mandiant reported september 16 that an attacker hijacked an active ai coding session at a saas provider and spread the shai-hulud worm across about 100 internal repositories, stealing secrets along the way.
your session token is now a supply chain.
Context
Mandiant's AI Risk and Resilience Report 2026 on Google Cloud describes a case in which a threat actor compromised a SaaS provider and hijacked an active AI coding assistant session on a developer's workstation. The assistant, operating as a trusted interpreter, recommended a poisoned package, the attacker installed an infostealer through a poisoned PyPI package, harvested GitHub OAuth tokens and deployed the self-propagating Shai-Hulud worm across approximately 100 internal code repositories. Its controls include verification hooks for AI-recommended dependencies, isolating local credentials, and treating AI coding assistants and MCP servers as privileged sessions.
The SaaS provider, hijacked active session, about 100 internal repositories and Shai-Hulud are first-party. Stealing secrets is a fair label for the OAuth tokens and infostealer named. The report page read shows no date, so September 16 is the coverage date and the report date is unresolved. The session is the new perimeter is the author's reading; the report says to treat assistants as privileged sessions without the word perimeter. It is one case study with an unnamed victim and is the report's own account, not independently checked.
Related work
- Earlier note on the same Mandiant case ↗Same case through The Hacker News.
- Earlier note on the Mandiant report ↗Same report.
Watch next
- The report's exact publication date.
Sources
- AI Risk and Resilience Report 2026 (Mandiant, Google Cloud)cloud.google.com
- Attacker hijacks AI coding assistant (The Hacker News, 16 Sep 2026)thehackernews.com
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 21 September 2026 at 04:38 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →