Malware

Sandworm_Mode Malware Targets AI Tools

July 23, 2026 04:03 · 12 min read
Sandworm_Mode Malware Targets AI Tools

Sandworm_Mode Malware: A Growing Threat to Software Development

Malware targeting AI coding assistants and software developers' automated workflows is spreading into more environments with more capabilities, placing defenders at a growing disadvantage. A malware strain dubbed Sandworm_Mode, first discovered by Socket in February, represents a growing threat to software development.

According to a CrowdStrike report, the self-propagating worm can spread through code repositories with minimal detection, raising alarms about software supply chains. The malware's capabilities are extensive, but not especially unique compared to the series of supply-chain worms known as Shai-Hulud, and more recently Mini Shai-Hulud.

A New Trend in Malware Attacks

Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, notes that this is a new trend in malware attacks. "This is something we're seeing more and more. It's the new hotness right now," he said. The malware targets and steals sensitive data, including credentials, keys, and secrets that unlock paths to additional services and dependencies throughout the AI toolchain.

This includes AI assistants, cloud providers, API keys for nine major LLM providers, CI/CD pipelines, and automated systems that build, test, and publish code. These actions blend in with tens of thousands of other commands occurring daily in any given environment infused with AI development tools.

Difficulty in Detection

Trying to find the signal of something malicious happening is very difficult because there's so much noise out there, according to Meyers. The worm also paces itself, setting multi-day delays to separate initial access from follow-on malicious activity — creating a gap in victims' telemetry windows, which makes it even more challenging for defenders to detect and attribute the chain of infection properly.

AI agents are pulling down all of these different dependencies continuously throughout the day, Meyers said. When you're looking downrange from the perspective of the security operations team, you're just seeing everybody pulling down these dependencies, and these dependencies self-unpacking and executing, so it just gets really, really noisy to try to find something bad happening.

Covering its Tracks

The malware covers its tracks further with a bit of a mean streak, by automatically destroying compromised environments if it can't spread or accomplish its objectives. "It's well thought-through, and well developed, so somebody spent some time caring and feeding this thing," Meyers said.

Despite CrowdStrike's four-month review of Sandworm_Mode, the cybersecurity firm has yet to gain a firm handle on its intent, but Meyers said it is designed to attain a strong foothold, which could enable long-term access. CrowdStrike hasn't determined who is responsible for the malware, yet Meyers said he doesn't think TeamPCP, a threat group that's been on a rampage through open-source software this year, is involved.

Unclear Intentions and Activity

The state of Sandworm_Mode and whether it remains active is also unclear. CrowdStrike said it continues to observe recently active malicious supply-chain packages that follow similar but technically divergent patterns. Ultimately, "the world has changed," Meyers said, adding that many attackers are pursuing similar paths in the AI toolchain, requiring defenders and threat hunters to place a greater focus on this burgeoning mode of aggression.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free