HackerFeeds

CyberSecurity News

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

The Hacker News
· September 16, 2026

AI summary

An attacker took control of an AI coding assistant session at a software-as-a-service provider and used it to spread malware called Shai-Hulud to around 100 internal code repositories. The attacker first poisoned software recommendations made by the assistant, which were then accepted. The malware, a worm, stole secrets and source code from the repositories. The incident involved the hijacking of an active session, allowing the attacker to carry out these malicious activities. The attacker's actions were facilitated by the acceptance of the tainted recommendations. The stolen information included repository secrets and source code.

Read the full article at The Hacker Newsthehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.