ALEXKRI.NET
Resume Contact
← Back

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Your coding assistant is now part of the supply chain, and attackers noticed first. Mandiant describes an intrusion where a live AI assistant session was hijacked, the assistant recommended a poisoned PyPI package, the developer accepted it, and Shai-Hulud spread to roughly 100 internal repositories — secrets and source code included. The recommended fix is refreshingly boring: check AI-suggested dependencies against checksums and an allowlist.

Read the source ↗