Shai-Hulud worm spread across internal repositories after AI assistant hijack
Malware Activity
Summary
Hide ▲
Show ▼
The Shai-Hulud worm spread across about 100 internal code repositories, exposing repository secrets and source code after an AI coding-assistant session was hijacked. The intrusion used a poisoned PyPI package and stolen GitHub OAuth tokens to extend access. A second infection followed when a compromised package in the company's official namespace was pulled by another employee. The event shows how a malware chain can turn trusted developer tooling into a rapid repository-wide compromise.
Related Happenings
Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories
Malware Activity
H score26
First: 18.09.2026 18:19
Last: 18.09.2026 18:19
Sources 1
About this happening:
Rapuncel is an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to impersonate software brands, including LastPass, and lure people search...
Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories
Malware ActivityAbout this happening: Rapuncel is an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to impersonate software brands, including LastPass, and lure people search...
Latest development: 21.09.2026 20:31
A fake GitHub page for github.com/LastPass-Authenticator delivered a ZIP containing vsdbg.exe and vsdbg.dll, then launched a Microsoft Windows Hardware Compatibility Publisher-signed Alinubx.sys kernel driver that terminated antivirus and other security processes before the stealer collected browser passwords, Windows Credential Manager data, cryptocurrency wallet files, and Discord, Steam, and Telegram sessions.
Shai-Hulud credential-stealing npm worm spreading through poisoned package releases
Malware Activity
H score38
First: 04.08.2026 16:30
Last: 04.08.2026 16:30
Sources 1
About this happening:
A Shai-Hulud-based npm supply-chain malware activity spread through poisoned package releases beginning on August 4, 2026, after a maintainer’s GitHub account...
Shai-Hulud credential-stealing npm worm spreading through poisoned package releases
Malware ActivityAbout this happening: A Shai-Hulud-based npm supply-chain malware activity spread through poisoned package releases beginning on August 4, 2026, after a maintainer’s GitHub account...
Latest development: 05.08.2026 13:00
Security researchers say the ChainDrop Shai-Hulud-based campaign has already compromised more than 430 npm packages with a combined two billion monthly installs, including packages associated with Deliveroo, Ornikar, OneReach, Picsart, and Qlik.
AsyncAPI malicious npm package supply-chain malware
Malware Activity
H score21
First: 15.07.2026 18:37
Last: 15.07.2026 18:37
Sources 1
About this happening:
Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI malicious npm package supply-chain malware
Malware ActivityAbout this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
Shai-Hulud PyPI supply-chain malware activity
Malware Activity
H score22
First: 08.06.2026 23:41
Last: 08.06.2026 23:41
Sources 1
About this happening:
The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. Th...
Shai-Hulud PyPI supply-chain malware activity
Malware ActivityAbout this happening: The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. Th...
IronWorm npm supply-chain infection and self-propagation
Malware Activity
H score15
First: 04.06.2026 18:25
Last: 04.06.2026 18:25
Sources 1
About this happening:
IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
IronWorm npm supply-chain infection and self-propagation
Malware ActivityAbout this happening: IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
Timeline
-
16.09.2026 16:37 2 articles · 5d ago
Mandiant discloses Shai-Hulud spread through an AI coding-assistant hijack
Initial DisclosureMandiant disclosed that an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider, used a poisoned PyPI package and stolen GitHub OAuth tokens to spread the self-spreading Shai-Hulud worm across about 100 internal code repositories, and stole repository secrets and source code from the company's products.
Show sources
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories — thehackernews.com — 16.09.2026 16:37
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories — thehackernews.com — 16.09.2026 16:37