logo

Malware is targeting AI tools in software development environments

ID: 3b31e4eb-37a7-57ad-858f-21416b4a2190

STIX ID: report--3b31e4eb-37a7-57ad-858f-21416b4a2190

Feed Name: CyberScoop

Threat Score
80/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Matt Kapko

...
...

Sandworm_Mode is a self-propagating supply-chain worm discovered in February that targets AI coding assistants and developer automation by spreading through code repositories and dependencies to harvest credentials, API keys (including keys for major LLM providers), CI/CD secrets, and cloud access. The worm blends malicious activity into noisy AI development workflows, uses multi-day pacing to evade detection, and can destructively wipe environments if unable to spread; CrowdStrike observed related malicious packages but attribution and full intent remain unclear.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.