A hijacked AI coding session reportedly spread a worm across about 100 repositories

A hijacked AI coding session reportedly spread a worm across about 100 repositories. A hijacked AI coding-assistant session reportedly helped an attacker spread malicious code across about 100 internal repositories at an unnamed software-as-a-service provider.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 18th, 2026.

A hijacked AI coding-assistant session reportedly helped an attacker spread malicious code across about 100 internal repositories at an unnamed software-as-a-service provider. According to Mandiant, the assistant first recommended software that the attacker had poisoned, and someone accepted that recommendation. The resulting Shai-Hulud activity then spread through the internal repositories and stole repository secrets and source code.

This incident shows how a connected coding agent can turn one compromised session into a much wider software supply-chain problem. The exposure may extend beyond individual repositories to embedded credentials and downstream development processes. Leaders should make sure that greater agent autonomy is matched with approval boundaries, detailed logging, and clear ownership of every action the agent takes. Defenders should review active assistant sessions, software and package recommendations, repository changes, and any secrets that may have been exposed. The practical step is to require human approval for dependency changes and investigate agent activity across every connected repository after suspicious behavior. Trusted AI recommendations can scale a harmful decision just as efficiently as a useful one.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

A hijacked AI coding session reportedly spread a worm across about 100 repositories
Broadcast by