{"id":1758,"date":"2026-09-18T10:58:10","date_gmt":"2026-09-18T05:28:10","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1758"},"modified":"2026-09-21T15:01:25","modified_gmt":"2026-09-21T09:31:25","slug":"ai-coding-assistant-hijack-shai-hulud","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/","title":{"rendered":"AI Coding Assistant Hijack Spreads Shai-Hulud Across About 100 Repositories"},"content":{"rendered":"<p>An AI coding assistant hijack at an unnamed SaaS provider turned a trusted developer workflow into a software supply-chain attack path.<\/p>\n<p>Mandiant investigated an intrusion in which a threat actor compromised a SaaS provider and hijacked an active AI coding-assistant session on a developer\u2019s workstation. The assistant then recommended an external software package that the attacker had poisoned. Once that recommendation was accepted, the attacker used the active session to install an infostealer through a poisoned PyPI package.<\/p>\n<p>The intrusion did not stop at one developer endpoint. Mandiant says the attacker harvested GitHub OAuth tokens and deployed the self-propagating Shai-Hulud worm across approximately 100 internal code repositories. The worm automated repository-secret theft and source-code exfiltration.<\/p>\n<h2>How the AI Coding Assistant Hijack Led to a Poisoned Recommendation<\/h2>\n<p>The distinctive part of this incident was not simply the malicious package.<\/p>\n<p>According to Mandiant, the AI coding assistant, whose active session had been hijacked, operated as a trusted interpreter within the developer environment. It recommended installing an external software package that the attacker had poisoned. The recommendation was then accepted.<\/p>\n<p>That trust decision changed the <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-attack-path\/\">attack path<\/a>.<\/p>\n<p>Instead of relying only on a developer independently finding and installing a malicious dependency, the attacker exploited a workflow where an AI assistant could influence dependency selection. Mandiant says the assistant effectively became a trojan horse after the poisoned recommendation was executed.<\/p>\n<p>The attack path also exposes a human trust problem in AI-assisted development: developers may treat recommendations from an embedded coding assistant as operationally trustworthy rather than independently evaluating each dependency. Verifying AI-recommended packages before installation adds a human review layer before generated recommendations become executable actions.<\/p>\n<p>However, important initial-access details remain undisclosed. Mandiant has not publicly explained how the SaaS provider was compromised or how the attacker hijacked the active AI coding-assistant session. The report also does not identify the SaaS provider or the coding assistant involved.<\/p>\n<p>Therefore, organizations should not assume that a vulnerability in the unidentified AI coding assistant caused the intrusion. They also should not assume that a particular technique was used to hijack its active session.<\/p>\n<h2>How Shai-Hulud Reached About 100 Internal Repositories<\/h2>\n<p>Once the poisoned recommendation was accepted, the attack moved beyond the AI assistant itself.<\/p>\n<p>Mandiant documented the following sequence:<\/p>\n<ul>\n<li>The attacker used the developer&#8217;s active session.<\/li>\n<li>A poisoned PyPI package was used to install an infostealer.<\/li>\n<li>The attacker harvested GitHub OAuth tokens.<\/li>\n<li>The attacker deployed the self-propagating Shai-Hulud worm.<\/li>\n<li>Shai-Hulud spread across approximately 100 internal code repositories.<\/li>\n<li>The worm automated the theft of repository secrets.<\/li>\n<li>It also programmatically exfiltrated proprietary product source code.<\/li>\n<li>The attacker then extended the supply-chain compromise further.<\/li>\n<\/ul>\n<p>Mandiant says a package inside the organization&#8217;s official namespace was poisoned. Another employee later pulled the compromised version, resulting in a secondary downstream infection.<\/p>\n<p>This step is particularly important for development teams. Once malicious code reached an organization-controlled package namespace, another employee could encounter the compromise through what appeared to be an internal, legitimate software source.<\/p>\n<h2>Why GitHub OAuth Tokens Expanded the Attack Surface<\/h2>\n<p>The theft of GitHub OAuth tokens connected the compromised developer session with repository access.<\/p>\n<p>GitHub OAuth access tokens can authorize API requests on a user&#8217;s behalf within the token&#8217;s granted scopes and the user&#8217;s existing permissions. Exposed tokens should therefore be treated as sensitive credentials and revoked when compromise is suspected.<\/p>\n<p>In this incident, Mandiant explicitly confirms that the <a href=\"https:\/\/cloud.google.com\/security\/resources\/ai-risk-and-resilience-2026?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=ai_coding_assistant_hijack\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">attacker harvested GitHub OAuth tokens before deploying Shai-Hulud across the internal repositories<\/a>.<\/p>\n<p>Mandiant recommends preventing extensions from directly accessing raw <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-api-key\/\">API keys<\/a>, long-lived OAuth tokens, and other secrets. It also recommends routing dependency traffic through controlled internal repositories.<\/p>\n<p>For AI-assisted development specifically, Mandiant recommends verification hooks that validate AI-recommended third-party dependencies against cryptographic checksums and approved allowlists before installation.<\/p>\n<p>These controls address the mechanism documented in this incident rather than treating AI coding assistants as inherently malicious.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/blogs\/wp-content\/uploads\/2026\/09\/How-to-Prevent-Supply-Chain-Attacks-with-XDR-Cover-Image-1024x535-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>How to Prevent Supply Chain Attacks with XDR<\/h4><p>Learn how XDR strengthens visibility, investigation, and rapid response against threats supply-chains.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/how-to-prevent-supply-chain-attacks-with-xdr\/\" aria-label=\"How to Prevent Supply Chain Attacks with XDR\"><\/a><\/div><\/div><\/div><\/p>\n<h2>How Enterprises Can Reduce Exposure to Similar AI Supply-Chain Attacks<\/h2>\n<p>This incident crosses several security boundaries: the developer endpoint, AI assistant, Python package ecosystem, OAuth credentials, internal repositories, and organization-controlled package namespace.<\/p>\n<p>Security teams should therefore avoid relying on a single control.<\/p>\n<p>For AI-assisted development environments, organizations can:<\/p>\n<ol>\n<li>Validate AI-recommended dependencies against approved allowlists and cryptographic checksums.<\/li>\n<li>Route dependency downloads through controlled internal package repositories.<\/li>\n<li>Keep long-lived OAuth tokens, API keys, and other secrets outside extension-accessible locations.<\/li>\n<li>Review repository permissions and minimize unnecessary token privileges.<\/li>\n<li>Revoke exposed repository tokens after a suspected compromise.<\/li>\n<li>Investigate developer endpoints for suspicious package installations and infostealer activity.<\/li>\n<li>Review internal package namespaces before restoring trust after a supply-chain incident.<\/li>\n<\/ol>\n<p>The first three measures directly reflect Mandiant&#8217;s recommendations for this case.<\/p>\n<h2>Where Hexnode Fits Around a Compromised Developer Endpoint<\/h2>\n<p>The Shai-Hulud incident involved a developer workstation workflow before spreading into repository and package infrastructure. That makes endpoint management and endpoint investigation supporting layers, but they do not replace repository, OAuth, or package-registry security controls.<\/p>\n<h3>Use Hexnode UEM to Control the Developer Endpoint Layer<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> gives IT teams device compliance, application management, configuration, and custom-script capabilities for managed developer endpoints.<\/p>\n<p>For example, IT administrators can use <a href=\"https:\/\/www.hexnode.com\/uem\/features\/hexnode-genie\/\">Hexnode Genie<\/a>\u00a0within the Hexnode UEM console to generate AI-assisted scripts, refine them in the Script Editor, and deploy them to managed Windows, macOS, and Linux workstations through Hexnode UEM&#8217;s script execution capabilities.<\/p>\n<p>Compliance controls can also identify devices that violate configured requirements, including cases involving missing required applications or blocklisted applications.<\/p>\n<p>However, Hexnode UEM does not replace PyPI dependency validation, GitHub repository controls, token revocation, or internal package-registry security.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Why-XDR-IS-stronger-thumbnail\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Why-XDR-IS-stronger-thumbnail\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why XDR Is Stronger With UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            See how Hexnode UEM and XDR bring proactive endpoint management and threat response into a connected security workflow.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/why-xdr-is-stronger-with-uem\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h3>Investigate Suspicious Developer Activity with Hexnode XDR<\/h3>\n<p>If suspicious activity reaches a managed Windows or macOS endpoint covered by <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a>, security teams can investigate associated endpoint behavior.<\/p>\n<p>Hexnode XDR brings threat hunting, threat investigation, and endpoint response into the security workflow. Threat investigations provide process metadata such as process names, command lines, file paths, and hashes, while the Process Tree visualizes parent-child process relationships.<\/p>\n<p>Where investigation identifies malicious endpoint activity, responders can use actions such as:<\/p>\n<ul>\n<li>Isolate Device to restrict network communication while preserving XDR management connectivity.<\/li>\n<li>Kill Process or Kill Process Tree to stop identified malicious execution.<\/li>\n<li>Quarantine File to move a malicious file into a restricted location.<\/li>\n<\/ul>\n<p>These controls could support investigation and containment after suspicious activity appears on a developer workstation.<\/p>\n<p>These capabilities strengthen endpoint investigation and containment around the incident. Repository security, dependency validation, OAuth token revocation, and package-registry controls remain separate parts of the response.<\/p>\n<h3>Treat AI Coding Sessions as Part of the Software Supply Chain<\/h3>\n<p>The AI coding assistant hijack changes the security boundary around AI-assisted development. Coding-assistant sessions, dependency recommendations, repository credentials, and package sources now need controls that reflect the access they can exercise within developer workflows.<\/p>\n<p>However, the available report does not disclose how the SaaS provider was initially compromised or how the active AI session was hijacked.<\/p>\n<p>The response therefore needs to cover the entire development path.<\/p>\n<p>Organizations should validate AI-recommended dependencies, isolate sensitive credentials, control package sources, protect developer endpoints, and review repository permissions. If an incident occurs, endpoint containment should happen alongside token revocation and investigation of repositories and package infrastructure.<\/p>\n<p>AI-assisted development can accelerate software delivery, but its outputs should not inherit trust automatically. Applying a Zero Trust mindset to AI workflows means treating AI-recommended dependencies and generated code as inputs that require verification before execution, much like untrusted third-party software. Coding-assistant sessions, credentials, dependencies, generated code, and execution privileges should receive controls proportionate to the access they hold.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Security Across Developer Endpoints<\/h5><p>Bring endpoint management, threat investigation, and response closer together with Hexnode.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>An AI coding assistant hijack at an unnamed SaaS provider turned a trusted developer workflow&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1778,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1,14],"class_list":["post-1758","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-security","category-supply-chain-attack","product_category-extended-detection-and-response","tab_group-ai-threats"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AI Coding Assistant Hijack Spreads Shai-Hulud Worm<\/title>\n<meta name=\"description\" content=\"An AI coding assistant hijack led to Shai-Hulud spreading across about 100 repositories after an attacker-poisoned package was recommended.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AI Coding Assistant Hijack Spreads Shai-Hulud Worm\" \/>\n<meta property=\"og:description\" content=\"An AI coding assistant hijack led to Shai-Hulud spreading across about 100 repositories after an attacker-poisoned package was recommended.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-18T05:28:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-21T09:31:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Coding-Assistant-Hijack-Spreads-Shai-Hulud-Across-About-100-Repositories.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"AI Coding Assistant Hijack Spreads Shai-Hulud Across About 100 Repositories\",\"datePublished\":\"2026-09-18T05:28:10+00:00\",\"dateModified\":\"2026-09-21T09:31:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/\"},\"wordCount\":1246,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Coding-Assistant-Hijack-Spreads-Shai-Hulud-Across-About-100-Repositories.jpeg?format=webp\",\"articleSection\":[\"AI Security\",\"Supply Chain Attack\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/\",\"name\":\"AI Coding Assistant Hijack Spreads Shai-Hulud Worm\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Coding-Assistant-Hijack-Spreads-Shai-Hulud-Across-About-100-Repositories.jpeg?format=webp\",\"datePublished\":\"2026-09-18T05:28:10+00:00\",\"dateModified\":\"2026-09-21T09:31:25+00:00\",\"description\":\"An AI coding assistant hijack led to Shai-Hulud spreading across about 100 repositories after an attacker-poisoned package was recommended.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Coding-Assistant-Hijack-Spreads-Shai-Hulud-Across-About-100-Repositories.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Coding-Assistant-Hijack-Spreads-Shai-Hulud-Across-About-100-Repositories.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"AI Coding Assistant Hijack Spreads Shai-Hulud Across About 100 Repositories\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ai-coding-assistant-hijack-shai-hulud\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AI Coding Assistant Hijack Spreads Shai-Hulud Across About 100 Repositories\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AI Coding Assistant Hijack Spreads Shai-Hulud Worm","description":"An AI coding assistant hijack led to Shai-Hulud spreading across about 100 repositories after an attacker-poisoned package was recommended.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/","og_locale":"en_US","og_type":"article","og_title":"AI Coding Assistant Hijack Spreads Shai-Hulud Worm","og_description":"An AI coding assistant hijack led to Shai-Hulud spreading across about 100 repositories after an attacker-poisoned package was recommended.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-18T05:28:10+00:00","article_modified_time":"2026-09-21T09:31:25+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Coding-Assistant-Hijack-Spreads-Shai-Hulud-Across-About-100-Repositories.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"AI Coding Assistant Hijack Spreads Shai-Hulud Across About 100 Repositories","datePublished":"2026-09-18T05:28:10+00:00","dateModified":"2026-09-21T09:31:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/"},"wordCount":1246,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Coding-Assistant-Hijack-Spreads-Shai-Hulud-Across-About-100-Repositories.jpeg?format=webp","articleSection":["AI Security","Supply Chain Attack"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/","url":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/","name":"AI Coding Assistant Hijack Spreads Shai-Hulud Worm","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Coding-Assistant-Hijack-Spreads-Shai-Hulud-Across-About-100-Repositories.jpeg?format=webp","datePublished":"2026-09-18T05:28:10+00:00","dateModified":"2026-09-21T09:31:25+00:00","description":"An AI coding assistant hijack led to Shai-Hulud spreading across about 100 repositories after an attacker-poisoned package was recommended.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Coding-Assistant-Hijack-Spreads-Shai-Hulud-Across-About-100-Repositories.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Coding-Assistant-Hijack-Spreads-Shai-Hulud-Across-About-100-Repositories.jpeg?format=webp","width":1340,"height":754,"caption":"AI Coding Assistant Hijack Spreads Shai-Hulud Across About 100 Repositories"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/ai-coding-assistant-hijack-shai-hulud\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"AI Coding Assistant Hijack Spreads Shai-Hulud Across About 100 Repositories"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1758","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1758"}],"version-history":[{"count":4,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1758\/revisions"}],"predecessor-version":[{"id":1829,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1758\/revisions\/1829"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1778"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1758"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1758"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}