Chronicle/Attacks & incidents

Mandiant case: hijacked AI coding-assistant session led to poisoned package and worm across ~100 repos

AttackIncidentSignificance assistant-drafted

Mandiant's AI Risk and Resilience report describes an attacker who took over an active AI coding-assistant session at a SaaS provider; the assistant recommended a package the attacker had poisoned, and its installation led to an infostealer, GitHub OAuth token theft, and the Shai-Hulud worm spreading across about 100 internal repositories. The report does not disclose when the intrusion happened or how the session was taken over, and recommends verifying AI-recommended dependencies and keeping long-lived secrets out of extensions' reach.

Why it matters

It is an incident-response account of an attacker using a trusted assistant's recommendation as the delivery step.

Key facts

As stated in the sources, with where to find them.

  • A second employee was infected after pulling a poisoned package from the company's official namespace.Mandiant report, case study 1
  • The report’s case study 6 describes a separate incident in which an accounting agent ran up $50,000 in cloud charges; Help Net Security reports it made more than 15,000 high-cost API calls in under an hour.Mandiant report, case study 6; Help Net Security

Findings that cite this record

No tracked finding cites this record yet.

Sources

Related records