logo

Attackers Are Learning to Live Off the AI Toolchain

ID: 6d4dc0ed-5804-5c32-9161-adf67ee3a34c

STIX ID: report--6d4dc0ed-5804-5c32-9161-adf67ee3a34c

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

Author: Jai Vijayan

...
...

Sandworm_Mode is a self-propagating worm distributed through 19 malicious npm packages that abuses AI coding assistants, CI pipelines, and developer workflows to steal credentials (npm, GitHub, cloud, crypto, LLM providers) and exfiltrate data via channels including DNS tunneling. The campaign hijacks CI workflows, uses Git hooks for persistence, performs prompt-injection against AI assistants via a rogue MCP server, and delays payload activation by 48–96 hours to evade correlation-based detections; CrowdStrike’s analysis found many behaviors indistinguishable from legitimate developer automation, highlighting a new, hard-to-detect supply-chain threat against AI toolchains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.