BMC Daily Cyber News

A hijacked AI coding session reportedly spread a worm across about 100 repositories. A hijacked AI coding-assistant session reportedly helped an attacker spread malicious code across about 100 internal repositories at an unnamed software-as-a-service provider.

Show Notes

Daily Cyber News: A hijacked AI coding session reportedly spread a worm across about 100 repositories

A hijacked AI coding-assistant session reportedly helped an attacker spread malicious code across about 100 internal repositories at an unnamed software-as-a-service provider. According to Mandiant, the assistant first recommended software that the attacker had poisoned, and someone accepted that recommendation. The resulting Shai-Hulud activity then spread through the internal repositories and stole repository secrets and source code.

Key context: This incident shows how a connected coding agent can turn one compromised session into a much wider software supply-chain problem.

For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

Topics: cybersecurity news, cybersecurity, cyber risk, hijacked, coding, session, reportedly, spread, worm, across.

What is BMC Daily Cyber News?

The BCM Daily Cyber News brings you clear, timely updates on threats, breaches, patches, and trends every day. Stay informed in minutes with focused audio built for busy professionals. Learn more and explore at BareMetalCyber.com.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 18th, 2026.

A hijacked AI coding-assistant session reportedly helped an attacker spread malicious code across about 100 internal repositories at an unnamed software-as-a-service provider. According to Mandiant, the assistant first recommended software that the attacker had poisoned, and someone accepted that recommendation. The resulting Shai-Hulud activity then spread through the internal repositories and stole repository secrets and source code.

This incident shows how a connected coding agent can turn one compromised session into a much wider software supply-chain problem. The exposure may extend beyond individual repositories to embedded credentials and downstream development processes. Leaders should make sure that greater agent autonomy is matched with approval boundaries, detailed logging, and clear ownership of every action the agent takes. Defenders should review active assistant sessions, software and package recommendations, repository changes, and any secrets that may have been exposed. The practical step is to require human approval for dependency changes and investigate agent activity across every connected repository after suspicious behavior. Trusted AI recommendations can scale a harmful decision just as efficiently as a useful one.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.