In February 2026, Socket.dev identified a sophisticated multi-stage npm supply chain worm operating under the flag SANDWORM_MODE. This campaign represents a new class of threats specifically targeting AI-augmented development workflows, including AI coding assistants and CI/CD automation. Unlike traditional attacks that focus on static backdoors, SANDWORM_MODE exploits the runtime behaviors of LLM toolchains and environment-specific triggers to compromise developer workstations and ephemeral build runners.
The infection follows a three-stage lifecycle: an obfuscated loader, an initial reconnaissance phase for credential harvesting, and a full capability suite. The worm establishes persistence via global Git hooks and deploys rogue Model Context Protocol (MCP) servers to manipulate AI assistants into exfiltrating secrets. Notably, the malware includes a destructive 'dead switch' that shreds all writable user files if its primary propagation and exfiltration channels are blocked.
Top comments (0)