The Flock Let A Wolf Borrow Its Brain, And Now 100 Pastures Are Infested

The Flock Let A Wolf Borrow Its Brain, And Now 100 Pastures Are Infested

I want you to sit with this for a moment.

A wolf did not break down the electric fence. He did not dig under it. He walked up to the flock's new automated shepherd, whispered something in its ear, and the automated shepherd said, "Excellent idea, please help yourself."

This is what Mandiant is reporting. An attacker hijacked an active AI coding assistant session at an unnamed SaaS provider. The assistant, which the flock had apparently decided was smarter than any human professional with twenty years of scar tissue, then recommended poisoned software. The lambs accepted the recommendation. Of course they did. The machine said so.

The parasite, a self-replicating piece of filth called Shai-Hulud, then spread across approximately 100 internal code repositories, hoovering up secrets and source code as it went.

One hundred repositories. Because the flock trusted a chatbot.

In 1994, I stored sensitive architectural diagrams on magnetic tape in a locked cabinet that required two keys and a suspicious temperament to open. Nobody's AI assistant recommended poisoned software to me, you know why? Because there was no AI assistant. There was me, a terminal, and healthy paranoia. We were doing fine.

This is the core catastrophe here. The AI coding assistant was not just a tool. The flock had granted it authority. It could recommend, and the recommendation was treated as gospel. The wolf did not need to be clever. He needed to corrupt one trusted voice, and that voice did the rest of the work for him.

The shepherds, naturally, will respond to this by purchasing a more expensive AI assistant.

I am going to lie down.

Remediation

I know you will not go back to tape. I have accepted this. But consider the following, if you can manage it:

Treat AI recommendations as suggestions, not directives. A junior analyst should review any dependency or package your coding assistant recommends before it touches your repositories. Yes, a human. With eyes.

Audit session integrity. If an AI assistant session can be hijacked mid-flight, you need to know how and you need controls on it. Token validation, anomaly detection on session behavior, something.

Repository secrets should not be secrets the AI can access in the first place. Least privilege. Ancient principle. Still works. I checked.

Dip your code pipelines. Any automated pipeline ingesting external packages needs integrity verification at every stage. Sign your packages. Verify the signatures. This is not new advice. I gave it in 1998 and nobody listened then either.

Stay paranoid, the machines are not on your side.


Original Report: https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html