Skip to main content
Back to articles
Security Solutions Team

CISO Daily Digest: AI Coding Assistant Session Hijacked — Shai-Hulud Worm Spreads Across ~100 Repositories (20260916)

Mandiant's new AI Risk and Resilience 2026 report documents how an attacker hijacked an active AI coding-assistant session at a SaaS provider — a poisoned package recommendation the assistant surfaced led to an infostealer, stolen GitHub OAuth tokens and the self-spreading Shai-Hulud worm across roughly 100 internal code repositories. Also today: EVA Air and Evergreen Aviation Technologies disclose intrusions; Elastic Security Labs tracks KREMLIN, a Brazilian banking malware ecosystem that regenerates Chromium integrity hashes; a joint FBI/NCSC/AIVD advisory exposes Iran's Telegram-controlled HEAVYGRAM spyware; and CISA adds the Google Pixel modem flaw CVE-2026-58704 to KEV with a September 19 deadline.

Mandiant AI-Coding-Assistant Shai-Hulud Supply-Chain PyPI OAuth EVA-Air Evergreen Taiwan TeamPCP KREMLIN REF9334 Banking-Malware Chrome Iran HEAVYGRAM CHOSEN-BRICK BambooToken MQTT WSO2 CVE-2026-5430 JWT WooCommerce CVE-2026-27540 LiteSpeed cPanel HBO-Max ClickFix PasteSwitch Pixel CVE-2026-58704 CISA-KEV Microsoft Patch-Tuesday RDS VectraRAT Parallels CVE-2026-90894 CRA ENISA PSIRT AWS AI-Security CISO-Digest

Hijacked AI Coding Assistant Session Spreads Shai-Hulud Across ~100 Repositories

Mandiant has published a case study — inside its new AI Risk and Resilience 2026 report — of an intrusion where an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service (SaaS) provider and ended up spreading the self-propagating Shai-Hulud worm across roughly 100 internal code repositories. The reported sequence: the assistant recommended third-party software that the attacker had poisoned, and the recommendation was accepted; the attacker then used the developer’s active session to install an infostealer through a poisoned PyPI package and steal GitHub OAuth tokens; the worm then spread through internal repositories and stole repository secrets and the source code for the company’s products. The attacker also poisoned a package in the company’s official namespace — another employee pulled the compromised version, producing a second infection. Mandiant’s public write-up does not say when the intrusion happened or how the attacker took over the assistant session.

The case sits inside a broader finding: across 2026, adversaries moved from prompting AI for research and troubleshooting to agentic attack orchestration — “the LLM is a participant rather than an advisor,” pivoting and deciding at machine speed. Google’s Threat Intelligence Group tracked attackers deploying agentic tools such as Hexstrike and Strix for autonomous reconnaissance, vulnerability validation and credential harvesting, supported by a growing ecosystem of proxy relays and account-pooling middleware built to bypass safety guardrails and billing limits. Earlier cases in the same report: the February weaponization of OpenClaw AI agent skills (backdoors and infostealers disguised as helpful automation packages, found by VirusTotal) and March incidents tied to UNC6780 (TeamPCP), which stole credentials for AI services and proprietary AI data using more than half a dozen exploitation methods. The report lands days after GTIG’s advisory on AI coding tools as a supply-chain attack surface, which we covered on September 14.

Why This Reshapes AI-Assisted Development Risk

  • One accepted AI recommendation became the intrusion path. The assistant surfaced software the attacker had poisoned; the developer accepted it; the attacker rode the same session into an infostealer and GitHub OAuth token theft. The assistant now sits inside the trust boundary of the development workstation.
  • Trust, not exploits, carried the payload across ~100 repositories. The worm spread itself, stole repository secrets and product source code, and re-infected through a package in the company’s own official namespace — the cascading failure ran through dependency trust chains, not a single vulnerable component.
  • 2026’s shift: the AI is a participant, not an advisor. Agentic tools (Hexstrike, Strix), middleware that bypasses guardrails and billing, and weaponized AI-agent skill packages all show operational tasks being offloaded at machine speed — a model where the model’s outputs are reviewed at human pace no longer matches attack tempo.
  • The suggested controls are still manual. Mandiant’s guidance for AI-assisted development: verify AI-recommended dependencies against cryptographic checksums and approved allowlists, keep long-lived tokens out of extensions’ reach, and route dependency traffic through controlled internal repositories — all steps that currently depend on someone remembering to do them.

🔗 Reference: Coverage from (The Hacker News, Google Cloud — Mandiant AI Risk and Resilience 2026)


Active Threats This Week

📌 Taiwan’s EVA Air and Evergreen Aviation Technologies disclose intrusions EVA Air (2618) and Evergreen Aviation Technologies (2645) filed cybersecurity material notices on Taiwan’s Market Observation Post System on the evening of September 15: EVA Air said an unknown party entered through a malicious IP address and obtained employee names and business contact information, assessing no impact on business operations; Evergreen Aviation Technologies said it detected attacks on parts of its internal information systems, isolated the affected devices, and reported core systems and operations normal with no customer or third-party personal data found leaked. Both companies activated incident-response procedures. The two are sister companies under the Evergreen Group, and iThome notes the near-simultaneous filings invite speculation the incidents may be linked — not yet confirmed by either company. 🔗 Reference: iThome | Taiwan News

📌 AFP and FBI charge two alleged TeamPCP principals: 1,000+ organizations, 500,000 credentials, 300 GB exfiltrated Two West Australian men — aged 21 and 23, arrested in the Perth-area suburbs of Cottesloe and Mandurah on August 26 — face a combined 14 charges over their alleged roles as principal participants in TeamPCP, the group behind this year’s largest developer supply-chain attacks (poisoned packages and workflows across Trivy, KICS, LiteLLM, the Telnyx SDK, SAP and TanStack tooling). The Australian Federal Police, the FBI and Western Australia Police estimate the malicious code potentially compromised more than 1,000 organizations worldwide, enabling the theft of over 500,000 credentials and exfiltration of at least 300 GB of data, with remediation costs in the hundreds of millions; a U.S. indictment against the alleged leader was unsealed, and authorities say further arrests have not been ruled out. The group’s tooling included the Mini Shai-Hulud worm and the CanisterWorm and SANDCLOCK credential harvesters. 🔗 Reference: iThome | Krebs on Security | U.S. DOJ

📌 KREMLIN: Brazilian banking malware regenerates Chromium integrity hashes to hijack Chrome and Edge Elastic Security Labs detailed an undocumented Brazilian banking malware operation it tracks as REF9334, active since at least May 2025: lures impersonating a dozen Brazilian banks lead victims to manually run a JavaScript file disguised as a banking, invoice or company document, which kick-starts multi-stage loaders and a custom C++ installer that plants a malicious browser extension on Google Chrome and Microsoft Edge. The extensions bypass Chromium’s integrity mechanisms — manipulating Secure Preferences and regenerating the required HMACs and App-Bound encrypted hashes — to steal credentials, session tokens and sensitive data. Command-and-control and payload locations are retrieved from Ethereum smart contracts acting as dead-drop resolvers, and the installer DLL-sideloads a legitimate SentinelOne binary (SentinelMemoryScanner.exe) whose unsigned fake SentinelAgentCore.dll payload checks CPU count and RAM to evade sandboxes and virtual machines. 🔗 Reference: The Hacker News | iThome

📌 FBI, NCSC and AIVD expose Iran’s Telegram-controlled HEAVYGRAM spyware A joint advisory published September 15 by the FBI, the UK’s NCSC and the Netherlands’ AIVD details Windows malware — called HEAVYGRAM by the FBI and CHOSEN BRICK by the NCSC — that Iran’s Ministry of Intelligence and Security uses to spy on dissidents, journalists and activists: it takes orders through Telegram, copies emails and chat messages, grabs screenshots and activates the microphone to record audio. The campaign dates to autumn 2023, and the agencies say it has been used against people in the UK, U.S. and Netherlands and worldwide since at least 2025; entry begins with a message posing as a known contact or as tech support for a messaging app, and often targets the work computer first, pivoting to a personal device if that fails. The advisory warns that victims’ personal details have appeared on pro-Iranian leak sites, raising personal-safety risks beyond data theft. 🔗 Reference: The Hacker News

📌 BambooToken: MQTT-controlled malware has hit Windows and Linux systems since at least 2023 Lumen Black Lotus Labs detailed BambooToken, a previously undocumented multi-platform malware family that uses the MQTT messaging protocol as its command channel to control Windows and Linux systems. Evidence points to activity since at least February 2023 with victims across Asia and South America and traffic as recent as July 2026; samples surfaced on VirusTotal in early 2026, most uploaded from Chinese IP space. Delivery borrows DLL sideloading through Tendyron’s “OnKey” software — the vendor’s PKI USB tokens are used for identity verification in high-security settings, with 190 million tokens claimed in circulation, and its website lists customers in China’s financial and government sectors. Initial access remains undetermined, and neither the vendor’s code-signing certificate nor its build environment was compromised — the attackers appear to rely on a sideloadable binary that targets are likely to have installed. 🔗 Reference: The Hacker News

📌 WSO2 API Manager CVE-2026-5430 exploitation under way — forged admin JWTs reach honeypots watchTowr reports active in-the-wild exploitation of CVE-2026-5430 (CVSS 9.8/10.0) in WSO2 API Manager: the service accepts JWTs signed with unsupported algorithms and approves them anyway, bypassing authentication for account takeover including administrative accounts — its honeypot network captured forged administrator-privileged JWT tokens arriving on September 13. Affected products: WSO2 API Manager 4.1.0 through 4.6.0, API Control Plane, Traffic Manager and Universal Gateway. WSO2’s advisory dates to May 2026; fixes ship through pull requests for community users and specific update levels for subscribers — with forged tokens granting access to every API backend endpoint and its credentials, unpatched gateways are the exposed tier. 🔗 Reference: The Hacker News

📌 WooCommerce Wholesale Lead Capture CVE-2026-27540: 100,000+ exploit attempts plant PHP web shells Wordfence warns that attackers are actively exploiting CVE-2026-27540 (CVSS 9.8) in Wholesale Lead Capture, a premium WooCommerce plugin with 6,000+ active installs: missing file-type validation in the wwlc_file_upload_handler AJAX action lets unauthenticated attackers upload PHP backdoors and achieve remote code execution. Wordfence has blocked more than 100,000 exploit attempts since June, with a spike past 40,000 attempts in a single day in late August; the uploaded shell reports host details and offers a browser-based upload form for writing additional malicious files. All versions up to 2.0.3.1 are affected — the fix is 2.0.3.2 or later (latest 2.0.6). Indicators include ten source IPs and requests to /wp-admin/admin-ajax.php with the wwlc_file_upload_handler action; site owners should also check the uploads directory for unexpected PHP files. 🔗 Reference: iThome | The Hacker News

📌 LiteSpeed Enterprise flaw lets one shared-hosting account reach root cPanel’s September 14 security advisory warns of a critical privilege-escalation vulnerability in LiteSpeed Web Server Enterprise before 6.3.7: a malicious low-privilege website user on a shared-hosting server can bypass account isolation — including CageFS — and gain root, then access or tamper with other sites and the server itself. LiteSpeed shipped 6.3.7 on September 11 with three security items in its changelog, but has not said which one addresses the escalation, so the root cause remains publicly unconfirmed. The advisory adds to a rough stretch for the shared-hosting stack: LiteSpeed’s cPanel plug-in had privilege-escalation issues disclosed in May and June. No in-the-wild exploitation has been reported so far. 🔗 Reference: iThome | The Hacker News

📌 HBO Max’s Reddit account hijacked for a 48-hour ClickFix malvertising blitz (PasteSwitch) Hudson Rock and ADAMnetworks traced a malvertising campaign to the hijacked verified Reddit account of HBO Max (u/hbomax), which pushed 108 malicious ads over about 48 hours. The ads steered users to lookalike pages across five lure themes — a fake HBO Max app for macOS (hbomaxx[.]app, 40 ads), developer and AI tooling (codex-craft[.]com, 36), a macOS disk-cleaning service (apple.clean-disk-guide[.]com, 15), code-desktop[.]com (11) and hbomax-macos[.]com (6) — then used ClickFix-style instructions that ask victims to paste an attacker-supplied command. macOS targets received MacSync and AMOS helper infostealers plus fake crypto wallets built to harvest seed phrases; Windows users received the InstallFix variant, loading the Amatera stealer in memory via PowerShell and HTA. Researchers tie the operation to the broader cross-platform PasteSwitch framework; Reddit has paused the ads and opened an investigation. 🔗 Reference: iThome | BleepingComputer

📌 Google Pixel modem flaw CVE-2026-58704 exploited — on CISA KEV with a September 19 deadline Google disclosed that CVE-2026-58704 (CVSS 8.0) — a privilege-escalation flaw in the Pixel cellular modem caused by a logic error that lets an attacker bypass permission checks — shows signs of “limited, targeted exploitation.” Exploitation is remote (proximal/adjacent) and requires no user interaction, making it usable as a zero-click attack. The September Pixel update fixes this flaw plus 109 others (46 critical), with patch levels of 2026-09-05 or later; CISA added the CVE to its KEV catalog on September 16 with a federal patch deadline of September 19. 🔗 Reference: The Hacker News

📌 Microsoft ships out-of-band fixes after its record 974-CVE Patch Tuesday broke RDS Microsoft issued out-of-band updates after this month’s record-setting Patch Tuesday (974 unique CVEs) caused problems in the field: Remote Desktop Services (RDS) connections that fail after a few minutes, failed logins, and RDS configuration-stage hangs on some Windows Server builds — plus unintended side effects for Hyper-V virtual machines and USB audio devices. The scale itself is the story: 974 CVEs in one release versus 909 in all of 2023, a volume security leaders attribute to AI-supercharged vulnerability reporting meeting a testing matrix no vendor can fully cover — SOCRadar’s CISO tells Dark Reading to expect patch-quality risk to grow with volume. 🔗 Reference: Dark Reading

📌 VectraRAT: a full-stack malware-as-a-service platform rents enterprise Windows access for $250 a month SOCRadar’s Threat Research Unit documented VectraRAT, a previously undocumented full-stack malware-as-a-service platform built entirely from scratch rather than forked from leaked RAT code: a Go control server (VectraHub) with an embedded Vue3 operator panel speaks a proprietary binary protocol to a native C++ Windows implant. Rented for from $250 per month (with crypting add-ons at $100–350), it delivers hidden-desktop control, remote shell, keylogging, clipboard hijacking, browser credential theft and a UAC bypass that elevates with no prompt; delivery rides the Amadey loader and ClickFix pages. Of 38 genuine victim sessions observed in under a week, 48% were corporate Windows editions — including Windows Server 2025 — with confirmed file exfiltration. The developer, tracking back to at least 2022 under the alias Nyxel, sells through HackForums, Exploit.in and Telegram. 🔗 Reference: Dark Reading | SOCRadar

📌 Parallels Desktop ‘ParaShells’ flaw (CVE-2026-90894) gives non-admin Mac users root — with no fix for Intel Macs JFrog published ParaShells, a local privilege-escalation flaw in Parallels Desktop for Mac: the root-running prl_disp_service listens on a world-writable socket, and the PrlSrv_LoginLocal call it accepts checks only kernel-reported credentials — no Parallels code signature and no admin rights required. From there, a tar --use-compress-program argument injection via the VM folder name turns into root: JFrog’s test script wrote a passwordless sudo rule and opened a root shell on Parallels Desktop 26.4.0 (Apple silicon). The flaw is tracked as CVE-2026-90894 (JFrog rates it 7.8) and is fixed in Parallels Desktop 27 — a version Intel Macs cannot install, leaving those users without a vendor fix. Exploitation requires existing local code execution on the Mac. 🔗 Reference: The Hacker News

📌 EU CRA reporting goes operational: ENISA’s Single Reporting Platform is live as Taiwan vendors build PSIRTs The EU Cyber Resilience Act’s vulnerability and incident reporting obligations took effect September 11, and ENISA launched the CRA Single Reporting Platform (SRP) the same day: manufacturers report once — within 24 hours (early warning) and 72 hours (notification), with a 14-day final report for actively exploited vulnerabilities and one month for severe incidents — and the information is routed to the relevant national CSIRTs. Open-source software steward obligations apply from December 11, 2027, when the CRA’s main requirements also start. For Taiwan: the National Institute of Cyber Security (資安院) says more vendors — especially those facing international customers and brands — are building or planning PSIRTs (Product Security Incident Response Teams), but warns maturity still lags: what counts is functioning vulnerability intake, analysis, patching and update processes with cross-department collaboration, not a team with the right name. 🔗 Reference: iThome | ENISA

📌 AWS ‘Deception Benchmark’: top AI models find real vulnerabilities but miss the false-positive bar AWS published Deception Benchmark, an evaluation of 12 leading AI models from five vendors on vulnerability judgment: under direct-judgment and Proof-of-Exploit (PoE) prompting — including cases where the attack path had already been blocked — the best configuration, Claude Opus 5 with PoE, reached 79.3% accuracy with a 24.9% false-positive and 16.8% false-negative rate; GPT-5.4 with PoE hit 77.7% accuracy with 10.1% false positives but 33.6% false negatives. Against a practical bar of keeping both error rates under 10%, no tested model configuration qualified — a caution for teams wiring AI into vulnerability triage and patch decisions. 🔗 Reference: iThome


How Can OPSWAT Help

Several of today’s threads run through files and packages entering trusted channels: the Mandiant case shows a poisoned PyPI package — and a poisoned package in a vendor’s own official namespace — doing the damage; KREMLIN arrives as a JavaScript file masquerading as a banking document; and the WooCommerce exploitation planted PHP web shells through file uploads. MetaDefender Multi-Scan layers 30+ anti-malware engines over files entering through email, web, upload and software-intake paths to catch what single-engine stacks miss; MetaDefender CDR (Content Disarm & Reconstruction) rebuilds allowed documents, archives and code artifacts — stripping active content before they reach users, CI runners or build systems; and MetaDefender Kiosk screens files at physical and OT boundaries.