Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories.
Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the company’s products.
The case appears in Mandiant’s September 2026 report. The public case study does not say when the intrusion happened or how the attacker took over the active coding-assistant session.
