Mandiant: attacker hijacks AI coding session, spreads Shai-Hulud to ~100 repos
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed SaaS firm, got a poisoned PyPI package accepted via the assistant’s recommendation, then spread the Shai-Hulud worm across about 100 internal repos and stole GitHub OAuth tokens and source. Defenders should checksum AI-recommended deps, keep secrets out of extension reach, and route installs through internal registries.