The Hacker NewsThursday · September 17, 2026FREE

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

securitysupply-chainai-assistantmalware

The Hacker News reported that an attacker hijacked a session of an AI coding assistant and used that access to spread Shai-Hulud across about 100 repositories. The report frames the event as a session hijacking, meaning the attacker operated through an already-established AI coding assistant session rather than a separate intrusion path, and it attributes the resulting spread of Shai-Hulud to that hijacked session. The source states the scope as roughly 100 repositories but does not identify the AI coding assistant, its vendor, the repositories involved, or the owners of those repositories. It also does not describe how the session was hijacked, what Shai-Hulud does once present, or whether any remediation or takedown occurred. No timeline beyond the publication date is given, and no affected-user or customer details are provided. The only concrete figures in the source are the approximate repository count and the malware name Shai-Hulud.

// why it matters

The report indicates that a compromised AI coding assistant session can be used to push malware into many repositories at once.

Sources

Primary · The Hacker News
▸ Read original at thehackernews.com

Like this? Get the next digest.