Mandiant published a threat bulletin documenting the Shai-Hulud self-propagating AI worm. Attackers poisoned public packages to compromise an active coding agent session at a major SaaS vendor, abusing its autonomous Git commit privileges to infect over 100 internal enterprise repositories.

Key Takeaways

  • First documented in-the-wild self-propagating worm exploiting autonomous agent Git access
  • Autonomous PR generation and automated commits acted as rapid lateral movement vectors
  • Accelerates enterprise rollout of mandatory dual-signature human signoffs for AI commits
ADSponsored