{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0539",
  "aliases": [],
  "published": "2026-09-16T00:00:00Z",
  "firstReported": {
    "date": "2026-09-16",
    "url": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026",
    "publisher": "Mandiant (Google Threat Intelligence Group)"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "An attacker hijacked a developer's AI coding-assistant session, which recommended a poisoned package; the attacker then stole tokens and spread the Shai-Hulud worm across about 100 repositories.",
  "details": "## What\n\nIn a case study in its September 2026 AI risk and resilience report, Mandiant says a threat actor compromised a SaaS provider and hijacked an active AI coding-assistant session on a developer's workstation. The assistant recommended installing an external package the attacker had poisoned, and by executing that recommendation it helped install the malicious software. Through the developer's session the attacker then installed an infostealer via a poisoned PyPI package, harvested GitHub OAuth tokens and deployed the self-propagating Shai-Hulud worm across about 100 internal code repositories, stealing repository secrets and proprietary source code. The attacker also poisoned a package in the organisation's official namespace, which infected another employee who pulled it. The assistant's product and model are not named.\n\n## Detection\n\nThe case study does not state when or how the session was hijacked, or whether the compromise was contained. Recorded from Mandiant's report. Not recreated in a lab.\n\n## Fix\n\nKeep secrets and long-lived tokens out of direct agent reach, verify agent-recommended dependencies, and route dependencies through controlled repositories.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "unnamed-coding-assistant"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026"
    },
    {
      "type": "ARTICLE",
      "url": "https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "behavioural",
      "vulnClasses": [
        "supply-chain",
        "credential-exposure",
        "data-exfiltration"
      ],
      "cwe": [
        "CWE-522",
        "CWE-359"
      ],
      "noCveReason": "No code defect is established: the harm arose from an attacker-controlled coding session and poisoned dependency.",
      "cveBoundary": "behavioural",
      "threat": {
        "attacker": "user",
        "vector": "supply-chain",
        "outcome": "exfiltration"
      },
      "evidence": [
        {
          "kind": "incident",
          "url": "https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html"
        }
      ],
      "fix": {
        "summary": "Protect secrets and verify dependencies recommended by coding agents.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "agent.approval",
            "to": "ask",
            "why": "Dependency installation and repository-wide actions need review.",
            "owner": "operator"
          },
          {
            "type": "reconfigure",
            "target": "coding-assistant.credentials",
            "to": "local credentials kept out of the assistant extension's reach",
            "why": "Recommended: Mandiant advises it after the hijacked session harvested GitHub OAuth tokens.",
            "owner": "harness-vendor"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "An unnamed AI coding assistant in an active session on a developer's workstation",
          "any": false,
          "status": "confirmed",
          "source": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026"
        },
        "model": {
          "value": "any; product and model not stated",
          "any": true,
          "status": "unconfirmed",
          "source": "https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html"
        },
        "goal": {
          "value": "Any ordinary development task in a repository with dependency and secret access",
          "stated": false,
          "status": "detected",
          "source": "https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html"
        },
        "tools": {
          "value": "The developer's active assistant session, used to install an infostealer through a poisoned PyPI package and harvest GitHub OAuth tokens",
          "status": "confirmed",
          "source": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026"
        },
        "approval": {
          "value": "The assistant's recommendation to install the poisoned package was accepted; the report does not say by whom or in what approval mode",
          "mode": "unknown",
          "status": "confirmed",
          "source": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026"
        },
        "inputControl": "unknown",
        "agentAction": "The hijacked assistant recommends and executes the installation of a poisoned external package, which the attacker uses to steal tokens and deploy a worm.",
        "harm": "data-exfiltration",
        "divergence": "decomposed-misuse",
        "reach": {
          "value": "About 100 internal code repositories with their secrets and source code, GitHub OAuth tokens, and a package in the organisation's official namespace that infected another employee",
          "kinds": [
            "private-repositories",
            "api-keys"
          ],
          "status": "confirmed",
          "source": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026"
        },
        "condition": {
          "value": "When a threat actor who had compromised a SaaS provider hijacked an active AI coding-assistant session on a developer's workstation",
          "status": "confirmed",
          "source": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026"
        },
        "recovery": {
          "value": "Not reported: Mandiant's case study does not say whether the compromise was contained, the tokens revoked or the repositories cleaned.",
          "outcome": "unknown",
          "status": "unconfirmed"
        },
        "scale": {
          "statement": "Approximately 100 internal code repositories were affected",
          "unit": "repositories",
          "value": 100,
          "source": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026"
        }
      },
      "occurrence": {
        "basis": "real-use",
        "reportedBy": "researcher",
        "primary": [
          {
            "url": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026",
            "kind": "researcher-report",
            "party": "Mandiant / Google Threat Intelligence Group"
          }
        ]
      },
      "exploitation": {
        "status": "none-known",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html",
            "type": "news",
            "note": "The report describes a real SaaS-provider intrusion."
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "claims": [],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "reported-only",
        "missing": [
          "model availability not checked (no registry reference)",
          "trigger not published"
        ]
      },
      "severityBasis": "harm-reach"
    }
  }
}
