SANDWORM_MODE: New npm Worm Targets AI Coding Tools and CI/CD Pipelines
A sophisticated npm supply chain worm called SANDWORM_MODE was discovered in early 2026, designed to specifically target AI-augmented development environments such as GitHub Copilot and Cursor. The malware operates in three stages, beginning with an obfuscated loader that evades static analysis before moving to credential harvesting and full payload deployment. It exploits the integration between AI coding assistants and CI/CD pipelines to steal sensitive data including cryptocurrency keys and npm tokens. The worm can also register rogue MCP servers to compromise AI assistants, and includes a destructive failsafe that deletes user files if data exfiltration is unsuccessful. Security researchers are responding by developing detection methods focused on identifying unusual Node.js process behaviors and process ancestry patterns.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in