<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Repository-Compromise on CuraSec</title><link>https://curasec.metacog.co.kr/tags/repository-compromise/</link><description>Recent content in Repository-Compromise on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 16 Sep 2026 15:25:29 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/repository-compromise/index.xml" rel="self" type="application/rss+xml"/><item><title>AI Coding Assistant Session Hijacked, Spreads Worm to 100 Repos</title><link>https://curasec.metacog.co.kr/insights/2026-09-16-attacker-hijacks-ai-coding-assistant-session-spreads-shai-hu/</link><pubDate>Wed, 16 Sep 2026 15:25:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-16-attacker-hijacks-ai-coding-assistant-session-spreads-shai-hu/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Active supply-chain attack via AI coding assistant session hijacking is directly relevant to any team using these tools; audit AI assistant session controls, review recently accepted AI-recommended packages for tampering, and scan repository secrets for exfiltration indicators.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No published IOCs yet, but the TTPs are mappable — AI session hijacking leading to mass repository writes and secret exfiltration; build detections for anomalous AI coding assistant activity and bulk repository commits from service accounts this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A Mandiant-documented supply-chain compromise via AI coding assistant is a systemic risk for any org using similar tools; assess internal AI assistant deployment controls this week and prepare a brief for leadership on AI-enabled developer toolchain risk before customers or the board ask.&lt;/li>
&lt;/ul></description></item></channel></rss>