Act
active
AI Coding Assistant Session Hijacked, Spreads Worm to 100 Repos
- Engineer — Act: Active supply-chain attack via AI coding assistant session hijacking is directly relevant to any team using these tools; audit AI assistant session controls, review recently accepted AI-recommended packages for tampering, and scan repository secrets for exfiltration indicators.
- SOC/IR — Plan: No published IOCs yet, but the TTPs are mappable — AI session hijacking leading to mass repository writes and secret exfiltration; build detections for anomalous AI coding assistant activity and bulk repository commits from service accounts this quarter.
- Leader — Act: A Mandiant-documented supply-chain compromise via AI coding assistant is a systemic risk for any org using similar tools; assess internal AI assistant deployment controls this week and prepare a brief for leadership on AI-enabled developer toolchain risk before customers or the board ask.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.