logo

Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks

ID: 3dad2deb-4603-5ea0-9211-f35b5d3a6038

STIX ID: report--3dad2deb-4603-5ea0-9211-f35b5d3a6038

Feed Name: Crowdstrike Blog

Threat Score
90/100

Date Published: 2026-07-21

Date Updated: 2026-07-23

Author: John Prieto

...
...

Socket.dev research describes SANDWORM_MODE, a highly sophisticated multi-stage npm supply-chain worm that targeted AI-driven development pipelines by using obfuscated loaders, environment fingerprinting, credential and crypto-key exfiltration, propagation via npm/GitHub/SSH, persistence through global git hooks, compromise of AI assistants/LLM toolchains, multi-channel exfiltration, and a destructive fallback; the report also outlines detection engineering efforts and deployed detections protecting customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.