Your AI coding assistant reads your repo, picks libraries, and writes imports. You accept suggestions because stopping to verify each one defeats the point of having the tool. That trust is exactly what attackers are now exploiting.
In September 2026, security researchers reported an attack that started inside a live AI coding assistant session at a software company. The assistant recommended a package, a developer installed it, and an infostealer hidden inside that package harvested their GitHub OAuth tokens. The Shai-Hulud worm then used those tokens to copy itself across roughly 100 internal repositories and steal source code and repository secrets.
How the attack unfolded
- An attacker gained control of an active AI coding assistant session belonging to a developer.
- The assistant recommended an outside package that looked legitimate.
- The developer installed it. The package came from PyPI and carried a hidden infostealer.
- The stealer collected source code, repository secrets, and high-privilege GitHub OAuth tokens.
- With those tokens, the Shai-Hulud worm self-replicated into about 100 internal repositories.
- A poisoned package appeared inside the company’s own internal namespace. A second employee pulled it and got infected.
Three routes attackers use to take over an assistant
The AI Risk and Resilience Report 2026 documents three methods that all end with the attacker controlling what your assistant recommends.
- Prompt injection. A group called TeamPCP planted instructions where an assistant would read and follow them as if the developer had typed them. They also targeted the LLM-based security scanners meant to catch such attempts, which then approved the same poisoned code.
- Tampered hooks. Attackers modified the command-line hooks an assistant runs on startup. Opening the project executed their code without any suggestion acceptance required.
- Weaponized agent skills. In February, attackers shipped OpenClaw agent skills bundled with backdoors, droppers, and infostealers. Most developers install agent skills the way they install a browser extension: without reading them.

The worm keeps expanding
A newer Shai-Hulud variant searches 469 locations for credentials, up from 189. The added targets include CI systems, cloud configuration files, and the settings files that AI development tools write to disk. Those files get created during installation and then forgotten, and teams keep finding access keys sitting in them in plain text.
The same report also documented an unrelated failure with no attacker involved: an autonomous agent hit a corrupted value, fell into a reasoning loop, fired more than 15,000 API calls in one hour, ran up roughly $50,000 in cloud bills, and locked a database hard enough to interrupt the business.
What to do now
- Treat any package your assistant suggests like a pull request from a stranger. Review it before it installs.
- Scan every dependency that lands in your lockfile in CI. Verify hashes against the registry rather than trusting the package name alone.
- Get long-lived tokens off developer laptops. Short-lived credentials and OIDC-based publishing limit what a stealer can take.
- Grep your AI tool config directories for secrets. If Shai-Hulud checks 469 locations, check those same locations first.
- Review agent skills, extensions, and MCP servers with the same scrutiny you apply to a dependency. They run with your permissions.
