Shai-Hulud worm spread across internal repositories after AI assistant hijack
Malware Activity
Summary
Hide ▲
Show ▼
The Shai-Hulud worm spread across about 100 internal code repositories, exposing repository secrets and source code after an AI coding-assistant session was hijacked. The intrusion used a poisoned PyPI package and stolen GitHub OAuth tokens to extend access. A second infection followed when a compromised package in the company's official namespace was pulled by another employee. The event shows how a malware chain can turn trusted developer tooling into a rapid repository-wide compromise.
Related Happenings
Shai-Hulud credential-stealing npm worm spreading through poisoned package releases
Malware Activity
H score38
First: 04.08.2026 16:30
Last: 04.08.2026 16:30
Sources 1
About this happening:
A Shai-Hulud-based npm supply-chain malware activity spread through poisoned package releases beginning on August 4, 2026, after a maintainer’s GitHub account...
Shai-Hulud credential-stealing npm worm spreading through poisoned package releases
Malware ActivityAbout this happening: A Shai-Hulud-based npm supply-chain malware activity spread through poisoned package releases beginning on August 4, 2026, after a maintainer’s GitHub account...
Latest development: 05.08.2026 13:00
Security researchers say the ChainDrop Shai-Hulud-based campaign has already compromised more than 430 npm packages with a combined two billion monthly installs, including packages associated with Deliveroo, Ornikar, OneReach, Picsart, and Qlik.
AsyncAPI malicious npm package supply-chain malware
Malware Activity
H score21
First: 15.07.2026 18:37
Last: 15.07.2026 18:37
Sources 1
About this happening:
Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI malicious npm package supply-chain malware
Malware ActivityAbout this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
Shai-Hulud PyPI supply-chain malware activity
Malware Activity
H score22
First: 08.06.2026 23:41
Last: 08.06.2026 23:41
Sources 1
About this happening:
The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. Th...
Shai-Hulud PyPI supply-chain malware activity
Malware ActivityAbout this happening: The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. Th...
IronWorm npm supply-chain infection and self-propagation
Malware Activity
H score15
First: 04.06.2026 18:25
Last: 04.06.2026 18:25
Sources 1
About this happening:
IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
IronWorm npm supply-chain infection and self-propagation
Malware ActivityAbout this happening: IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
Red Hat npm Namespace Hijacked in Supply Chain hit by cyberattack
Incident
H score13
First: 01.06.2026 20:40
Last: 01.06.2026 20:40
Sources 1
About this happening:
Red Hat's official npm namespace was hijacked in a supply chain attack that republished 32 packages in the @redhat-cloud-services scope on June 1, 2026. The ma...
Red Hat npm Namespace Hijacked in Supply Chain hit by cyberattack
IncidentAbout this happening: Red Hat's official npm namespace was hijacked in a supply chain attack that republished 32 packages in the @redhat-cloud-services scope on June 1, 2026. The ma...
Timeline
-
16.09.2026 16:37 2 articles · 2h ago
Mandiant discloses Shai-Hulud spread through an AI coding-assistant hijack
Initial DisclosureMandiant disclosed that an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider, used a poisoned PyPI package and stolen GitHub OAuth tokens to spread the self-spreading Shai-Hulud worm across about 100 internal code repositories, and stole repository secrets and source code from the company's products.
Show sources
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories — thehackernews.com — 16.09.2026 16:37
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories — thehackernews.com — 16.09.2026 16:37