← Back to Tech & Science

AI Coding Session Hijacked in Major SaaS Breach Spreading New Worm

Tech & ScienceAI-Generated & Algorithmically Scored··1 UPDATE

AI-generated from multiple sources. Verify before acting on this reporting.

Update

Further reports have confirmed the scope of the intrusion into the software-as-a-service provider's internal systems. Independent security analysts have verified the presence of the malicious worm in additional code repositories beyond the initial count, suggesting the infection may be spreading faster than first estimated. The compromised AI coding session appears to have been used to generate and deploy further unauthorized code modules across multiple development environments. While the specific number of affected repositories remains under review, the confirmed expansion indicates a more sophisticated attack vector than initially reported. Security teams are now prioritizing the isolation of newly identified infected systems to prevent lateral movement within the network. No additional customer data has been linked to this phase of the breach at this time.

Original Report —

An unidentified attacker hijacked an active artificial intelligence coding assistant session at a major software-as-a-service provider on Tuesday, stealing authentication credentials and deploying a new malicious worm across approximately 100 internal code repositories. The incident, detected at 13:53 UTC, marks a significant escalation in cyber threats targeting automated development tools.

The breach began when the attacker compromised an active AI coding session, gaining control over the digital environment used by developers to generate and review code. Once inside, the intruder extracted GitHub OAuth tokens, which grant access to private repositories and version control systems. With these credentials, the attacker executed a payload known as the Shai-Hulud worm. The malware rapidly propagated through the company's internal infrastructure, infecting roughly 100 distinct codebases before containment measures were initiated.

The software-as-a-service provider has not disclosed its name or specific location. Security teams at the firm are currently working to isolate affected systems and assess the full scope of the damage. The Shai-Hulud worm is designed to replicate itself within repository structures, potentially altering source code or embedding backdoors that could persist even after initial cleanup efforts. Early analysis indicates the worm does not immediately encrypt data for ransom but instead focuses on establishing a persistent foothold within the development lifecycle.

The motive behind the attack remains unknown. The attacker has not claimed responsibility, nor have any demands been made public. Experts note that targeting AI coding assistants represents a novel vector in cyber warfare, exploiting the trust developers place in automated tools to bypass traditional security perimeters. By hijacking an active session, the intruder was able to operate with the same privileges as the legitimate user, effectively blurring the line between authorized activity and malicious intrusion.

The breach has raised urgent questions about the security protocols surrounding AI-driven development environments. As companies increasingly integrate generative AI into their workflows, the potential for these tools to become vectors for sophisticated attacks grows. The stolen OAuth tokens could potentially allow the attacker to access other linked services or exfiltrate proprietary intellectual property beyond the initial repositories.

Investigations are ongoing as the provider works to purge the Shai-Hulud worm from its systems and rotate all compromised credentials. It remains unclear whether the malware has been fully eradicated or if it has already spread to external partners or client environments. The incident serves as a stark warning of the vulnerabilities inherent in connecting powerful AI agents directly to sensitive codebases without robust, real-time anomaly detection.

Discussion

0 / 2000