SPIN Unprocessed September 16, 2026 ai_technology cybersecurity
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
View original on thehackernews.comOverview
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the
SpinGraph analysis pending — check back after processing.
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
More from The Hacker News
View all →- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
- One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
- Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO