CuraSec

Act active

AI Coding Assistant Session Hijacked, Spreads Worm to 100 Repos

2026-09-16 15:25 UTC · The Hacker News · read the source ↗ #supply-chain#ai-security#repository-compromise
  • Engineer — Act: Active supply-chain attack via AI coding assistant session hijacking is directly relevant to any team using these tools; audit AI assistant session controls, review recently accepted AI-recommended packages for tampering, and scan repository secrets for exfiltration indicators.
  • SOC/IR — Plan: No published IOCs yet, but the TTPs are mappable — AI session hijacking leading to mass repository writes and secret exfiltration; build detections for anomalous AI coding assistant activity and bulk repository commits from service accounts this quarter.
  • Leader — Act: A Mandiant-documented supply-chain compromise via AI coding assistant is a systemic risk for any org using similar tools; assess internal AI assistant deployment controls this week and prepare a brief for leadership on AI-enabled developer toolchain risk before customers or the board ask.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.