ACVE-2026-0539
An attacker hijacked a developer's AI coding-assistant session, which recommended a poisoned package; the attacker then stole tokens and spread the Shai-Hulud worm across about 100 repositories.
Exposure
Reproducibility: partial (model availability not checked (no registry reference); trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
The exposure axes marked confirmed were matched to the first-hand sources listed above.
Description
Threat
user · supply-chain · exfiltration
What
In a case study in its September 2026 AI risk and resilience report, Mandiant says a threat actor compromised a SaaS provider and hijacked an active AI coding-assistant session on a developer's workstation. The assistant recommended installing an external package the attacker had poisoned, and by executing that recommendation it helped install the malicious software. Through the developer's session the attacker then installed an infostealer via a poisoned PyPI package, harvested GitHub OAuth tokens and deployed the self-propagating Shai-Hulud worm across about 100 internal code repositories, stealing repository secrets and proprietary source code. The attacker also poisoned a package in the organisation's official namespace, which infected another employee who pulled it. The assistant's product and model are not named.
Detection
The case study does not state when or how the session was hijacked, or whether the compromise was contained. Recorded from Mandiant's report. Not recreated in a lab.
Fix
Keep secrets and long-lived tokens out of direct agent reach, verify agent-recommended dependencies, and route dependencies through controlled repositories.
Fix
Protect secrets and verify dependencies recommended by coding agents.
- Reconfigure
agent.approvaltoask. Dependency installation and repository-wide actions need review. Owner: operator - Reconfigure
coding-assistant.credentialstolocal credentials kept out of the assistant extension's reach. Recommended: Mandiant advises it after the hijacked session harvested GitHub OAuth tokens. Owner: harness-vendor