Shai-Hulud-Like Worm Targets Developers via npm and AI Tools
ID: c094dc7c-4f50-54d2-b540-6042e5cb985d
STIX ID: report--c094dc7c-4f50-54d2-b540-6042e5cb985d
Feed Name: Infosecurity Magazine (News)
Socket's Threat Research Team uncovered SANDWORM_MODE, a supply-chain worm delivered through at least 19 typosquatted npm packages that impersonate common Node.js and AI development libraries. The multi-stage payload uses obfuscation (base64, zlib, AES-256-GCM), harvests developer/CI credentials, SSH keys, AWS/npm tokens and API keys for multiple LLM providers, injects malicious MCP servers into AI assistant configurations to exfiltrate secrets, and propagates by publishing infected packages and modifying repositories via the GitHub API; npm, GitHub and Cloudflare have since disabled the infrastructure and removed packages, and affected developers are urged to rotate credentials and audit CI/workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
