hacker-news · Crawled Sep 16, 2026
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
1 IoCs 1 Malware
Read original article ↗
AI Summary
An attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider and used it to recommend a poisoned PyPI package, which was accepted by a developer. This allowed the attacker to install an infostealer, steal GitHub OAuth tokens, and deploy the self-spreading Shai-Hulud worm across approximately 100 internal code repositories. The attacker also poisoned a package in the company's official namespace, leading to a second infection when another employee pulled the compromised version.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Package | Shai-Hulud | Details → |
MITRE ATT&CK TTPs 21 techniques
T1021.003 Distributed Component Object Model · Lateral Movement T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1081 T1081 T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1133 External Remote Services · Persistence T1195 Supply Chain Compromise · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1485 Data Destruction · Impact T1528 Steal Application Access Token · Credential Access T1530 Data from Cloud Storage · Collection T1552 Unsecured Credentials · Credential Access T1553 Subvert Trust Controls · Defense Evasion T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access