{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/mandiant-hijacked-coding-assistant-shai-hulud-2026/",
 "asOf": "2026-09-26",
 "id": "mandiant-hijacked-coding-assistant-shai-hulud-2026",
 "date": "2026-09-16",
 "datePrecision": "day",
 "title": "Mandiant case: hijacked AI coding-assistant session led to poisoned package and worm across ~100 repos",
 "lane": "attack",
 "kind": "incident",
 "summary": "Mandiant's AI Risk and Resilience report describes an attacker who took over an active AI coding-assistant session at a SaaS provider; the assistant recommended a package the attacker had poisoned, and its installation led to an infostealer, GitHub OAuth token theft, and the Shai-Hulud worm spreading across about 100 internal repositories. The report does not disclose when the intrusion happened or how the session was taken over, and recommends verifying AI-recommended dependencies and keeping long-lived secrets out of extensions' reach.",
 "whyItMatters": "It is an incident-response account of an attacker using a trusted assistant's recommendation as the delivery step.",
 "actors": [
  "mandiant"
 ],
 "topics": [
  "agent-supply-chain",
  "ai-enabled-intrusion",
  "threat-intelligence"
 ],
 "atlas": [
  "supply-chain",
  "credentials",
  "human-approver"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026",
   "publisher": "Mandiant (Google Cloud)",
   "title": "AI Risk and Resilience Report 2026",
   "type": "primary",
   "accessed": "2026-09-26",
   "shared": true
  },
  {
   "url": "https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html",
   "publisher": "The Hacker News",
   "title": "Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories",
   "date": "2026-09-16",
   "type": "secondary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://www.helpnetsecurity.com/2026/09/16/google-mandiant-enterprise-ai-security-risks-report/",
   "publisher": "Help Net Security",
   "title": "One runaway AI agent racked up a $50,000 cloud bill",
   "date": "2026-09-16",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "A second employee was infected after pulling a poisoned package from the company's official namespace.",
   "locator": "Mandiant report, case study 1"
  },
  {
   "fact": "The report’s case study 6 describes a separate incident in which an accounting agent ran up $50,000 in cloud charges; Help Net Security reports it made more than 15,000 high-cost API calls in under an hour.",
   "locator": "Mandiant report, case study 6; Help Net Security"
  }
 ],
 "significance": 4,
 "fideQuestions": [
  "FID-076"
 ],
 "methods": [],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}