Find notable cyber news and cases, enriched with sources, timelines, and signals.

Shai-Hulud worm spread across internal repositories after AI assistant hijack

Malware Activity
First reported
Last updated
Happening score
H score 12
1 unique sources, 1 articles

Summary

Hide ▲

The Shai-Hulud worm spread across about 100 internal code repositories, exposing repository secrets and source code after an AI coding-assistant session was hijacked. The intrusion used a poisoned PyPI package and stolen GitHub OAuth tokens to extend access. A second infection followed when a compromised package in the company's official namespace was pulled by another employee. The event shows how a malware chain can turn trusted developer tooling into a rapid repository-wide compromise.

Related Happenings

Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories

Malware Activity
H score26 First: 18.09.2026 18:19 Last: 18.09.2026 18:19 Sources 1

About this happening: Rapuncel is an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to impersonate software brands, including LastPass, and lure people search...

Latest development: 21.09.2026 20:31

A fake GitHub page for github.com/LastPass-Authenticator delivered a ZIP containing vsdbg.exe and vsdbg.dll, then launched a Microsoft Windows Hardware Compatibility Publisher-signed Alinubx.sys kernel driver that terminated antivirus and other security processes before the stealer collected browser passwords, Windows Credential Manager data, cryptocurrency wallet files, and Discord, Steam, and Telegram sessions.

Shai-Hulud credential-stealing npm worm spreading through poisoned package releases

Malware Activity
H score38 First: 04.08.2026 16:30 Last: 04.08.2026 16:30 Sources 1

About this happening: A Shai-Hulud-based npm supply-chain malware activity spread through poisoned package releases beginning on August 4, 2026, after a maintainer’s GitHub account...

Latest development: 05.08.2026 13:00

Security researchers say the ChainDrop Shai-Hulud-based campaign has already compromised more than 430 npm packages with a combined two billion monthly installs, including packages associated with Deliveroo, Ornikar, OneReach, Picsart, and Qlik.

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

Shai-Hulud PyPI supply-chain malware activity

Malware Activity
H score22 First: 08.06.2026 23:41 Last: 08.06.2026 23:41 Sources 1

About this happening: The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. Th...

IronWorm npm supply-chain infection and self-propagation

Malware Activity
H score15 First: 04.06.2026 18:25 Last: 04.06.2026 18:25 Sources 1

About this happening: IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...

Timeline

  1. 16.09.2026 16:37 2 articles · 5d ago

    Mandiant discloses Shai-Hulud spread through an AI coding-assistant hijack

    Initial Disclosure

    Mandiant disclosed that an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider, used a poisoned PyPI package and stolen GitHub OAuth tokens to spread the self-spreading Shai-Hulud worm across about 100 internal code repositories, and stole repository secrets and source code from the company's products.

    Show sources