Key Facts
Mandiant’s AI Risk and Resilience Report 2026 describes an incident in which an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider.
Technical Details
The Hacker News reports that the attacker used a poisoned package recommended by the assistant, installed an infostealer, stole GitHub OAuth tokens, and spread the Shai-Hulud worm to about 100 internal repositories. The public case study does not identify the affected organization or describe how the session was taken over.
Impact & Mitigation
Mandiant recommends validating AI-recommended dependencies with approved allowlists and cryptographic checksums, limiting extension access to long-lived credentials, and routing dependencies through controlled internal repositories.
