Hijacked AI coding session spreads compromise across about 100 repositories

Hijacked AI coding session spreads compromise across about 100 repositories. A compromised software development workflow allowed malicious activity to spread across about 100 internal code repositories.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, September 17th, 2026.

A compromised software development workflow allowed malicious activity to spread across about 100 internal code repositories. Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider. Before that repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The resulting Shai-Hulud activity stole repository secrets and source code.

This matters because one trusted AI-assisted decision can quickly become a supply-chain problem. Development teams and internal applications may be exposed when secrets and source code are taken, and the consequences can move downstream if compromised components enter other systems.

Leaders should govern AI coding tools like other privileged production systems rather than treating them as ordinary productivity software. Defenders should limit repository permissions, independently review dependency recommendations and monitor unusual changes across connected projects. The broader lesson is that AI speed can magnify a compromised decision before a human reviewer understands its reach. Restrict coding assistants to least privilege and require independent review before accepting new dependencies or broad repository changes.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Hijacked AI coding session spreads compromise across about 100 repositories
Broadcast by