Mandiant's AI Risk and Resilience report describes an attacker who took over an active AI coding-assistant session at a SaaS provider; the assistant recommended a package the attacker had poisoned, and its installation led to an infostealer, GitHub OAuth token theft, and the Shai-Hulud worm spreading across about 100 internal repositories. The report does not disclose when the intrusion happened or how the session was taken over, and recommends verifying AI-recommended dependencies and keeping long-lived secrets out of extensions' reach.
Why it matters
It is an incident-response account of an attacker using a trusted assistant's recommendation as the delivery step.
Key facts
As stated in the sources, with where to find them.
- A second employee was infected after pulling a poisoned package from the company's official namespace.Mandiant report, case study 1
- The report’s case study 6 describes a separate incident in which an accounting agent ran up $50,000 in cloud charges; Help Net Security reports it made more than 15,000 high-cost API calls in under an hour.Mandiant report, case study 6; Help Net Security
Findings that cite this record
No tracked finding cites this record yet.
Sources
Related records
Sep 8, 2026
September 2026
May 11, 2026
Sep 25, 2026
Feb 25, 2026
Jun 3, 2026