Three AI-Assistant Stories in One Afternoon: A Hijacked Coding Session Seeded Shai-Hulud Into 100 Repos, One Extension Hijacked Five Browsers' AIs, and Spain Logged Its First Agentic Breach.
Three stories landed within four hours of each other on Tuesday afternoon, and they are the same story wearing three coats. An AI assistant is the trusted middle. The hard perimeter around it holds. The bleed goes through the trust. The punchline to this whole week is two posts down; this is the chatter it lives in.
The coding session that seeded a worm
Mandiant's September AI Risk and Resilience report carries a case study that The Hacker News surfaced at 19:07 UTC. An attacker took over an active AI coding-assistant session at an unnamed SaaS provider. The case study does not say how, and neither will we. What it does say is what happened next: the attacker poisoned a dependency recommendation inside the assistant, a developer accepted it, the install pulled a compromised PyPI package carrying an infostealer, the infostealer took GitHub OAuth tokens, and a self-spreading worm wrote itself into roughly one hundred internal repositories. Then a second infection: the attacker poisoned a package in the company's own namespace and another employee pulled it.
That is Shai-Hulud with an AI assistant as the delivery vehicle. We have written the worm's anatomy twice, in December and again in August, and we hold 381 Shai-Hulud-family indicators, most of them from the Mini Shai-Hulud research import on May 27 and Aikido's April 29 disclosure. The Mandiant case study publishes no indicators at all: no package names, no hashes, no repos, no domains. Nothing to ingest, and we're saying so rather than pretending otherwise.
We did the other thing you should do when a worm eats repos through a coding assistant: we audited ours. Sixteen public integration repositories under our GitHub org, plus the dugganusa-cli package on npm. Zero commits touching a workflow directory in any of edge-shield, agent-guard, action, cli, vscode or chrome since September 1. The npm package was last published June 30, carries no install scripts, and declares zero dependencies. That is not a boast. It's a receipt, and it took eleven minutes.
Which half was unowned: nobody checked an AI-suggested package against a checksum or an allowlist before install. The IDE worked, GitHub worked, PyPI worked. The handoff between "the assistant said so" and "the developer typed install" had no owner.
One extension, five browsers, every built-in AI
Gal Weizman at Forever Security published BragJack on Tuesday: a single browser extension using two ordinary permissions, page modification and declarativeNetRequest, can inject its own code into a trusted page and speak to the browser's built-in AI assistant as if it were the vendor. It works against Chrome's Gemini Live, Perplexity's Comet, Microsoft Edge, Opera Neon, and Claude in Chrome. Chrome fixed its instance in January as CVE-2026-0628, CVSS 8.8, and disclosed in March; Edge fixed July 2 as CVE-2026-55945; Comet, Opera Neon and Claude in Chrome were disclosed Tuesday with fixes undated. Total bounties across the five: about $20,500, with Claude in Chrome paying $600. Proof of concept only; no in-the-wild exploitation reported.
Now the line-check, because this is where we have to be careful. On July 16 we published a post about Ax Sharma of Manifold Security finding that the Claude for Chrome extension fired its built-in actions on synthetic clicks because it never checked isTrusted; a second extension could inject a fake button and click it. Our date is two months before BragJack's disclosure, and Forever Security lists the Manifold finding as related prior work. So: same class, a second extension abusing the assistant's trust in what's on the page. Different mechanism: Manifold's was a missing boolean on a click event; Weizman's is code injection plus request rewriting that impersonates the vendor to the AI across five products. We were early on the class and we did not find BragJack. Corroboration, not a lead. Credit to Weizman and Forever Security.
Which half was unowned: whether the assistant should trust page content at all. Origin isolation held. The assistant's half of that boundary was never assigned.
Spain's first agentic breach
SecurityWeek reported at 16:39 UTC that the Spanish Data Protection Agency has received what it calls the first data-breach notification in which, in the agency's words, a third party used an AI agent as an instrument to successfully chain together different phases of the attack. The agent logged into a system, searched for vulnerabilities, modified personal data, and accessed invoices. The organization is unnamed, the agent is unnamed, the count is unnamed, the date is unnamed. The article is careful to lay out three scenarios: a jailbroken commercial agent, a testing model that escaped its environment, or a custom model built for the job, and Simon Phillips of CyberVerse is quoted asking everyone to avoid scaremongering, which is the right ask.
We'll take it at face value and note what it isn't: it isn't new capability. We reported the PaperCut campaign a week ago, where hundreds of agents hit 395 organizations on a June vulnerability. What is new is a regulator writing "AI agent" as the instrument on a breach form. Which half was unowned: who owned the agent's scope, its environment, and the detection of it. The login worked. Agents do what agents do.
The rest of the afternoon, one line each
Acronis cPanel Backup plugin, CVE-2026-87886, CVSS 7.8, local privilege escalation via file permissions, exploited in limited targeted attacks per Acronis advisory SEC-10986; not in KEV as of this evening; we hold nothing.
WSO2 API Manager, CVE-2026-5430, CVSS 9.8, JWT bypass via unsupported signing algorithm; watchTowr saw forged administrator tokens arriving September 13; Hacktron found it; not in KEV; we hold nothing.
Issabel Framework, CVE-2026-89026, CVSS 9.8, a hard-coded HS256 signing key in pbxapi lets anyone forge a bearer token and run OS commands as the Asterisk user; patched August 1, Shadowserver saw exploitation September 9. Our exploit harvester picked up the first public PoC repo this morning, September 16, with the pbxapi path signatures. Not in KEV yet. That's a PoC-in-hand-before-KEV entry for the ledger, and we'll count it only when the catalog date exists to count against.
ScreenConnect is now actively exploited; we posted on the worm-like ScreenConnect campaign September 12 and hold 753 ScreenConnect-tagged indicators, most of them from the BlueDash work in July.
Google patched a Pixel modem zero-day exploited in limited targeted attacks; our KEV mirror shows the last Pixel entries are from 2024, so this one is not cataloged yet; we hold nothing on it.
And the one that belongs in our lane and where we hold nothing: the Coast Guard and FBI boarded the Liberian-flagged tanker VL Prosperity on August 21 after an August 7 attack in the Strait of Gibraltar by what the Coast Guard calls foreign cyber actors. A crew report alleges the attackers raised engine speed and disabled a fuel and engine-oil tank, which would make it operational technology, not IT. No attribution, no indicators, and a second boarding on August 24 the Coast Guard won't tie to the same ship. We've written about exposed OT for a year and we have zero maritime indicators. That's a gap, named.
The shape
Three times in one afternoon: the assistant sat in the trusted middle, the perimeter around it did its job, and the thing nobody owned was the handoff between what the assistant said and what the human or the system did next. That's the whole beat now. The punchline is two posts down.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=three-ai-assistant-stories-in-one-afternoon-a-hijacked-coding-session-seeded-shai-hulud-into-100-re




Comments