{"slug": "malware-is-targeting-ai-tools-in-software-development-environments", "title": "Malware is targeting AI tools in software development environments", "summary": "A self-propagating malware strain called Sandworm_Mode is targeting AI coding assistants and software development environments, stealing credentials, API keys, and secrets across the AI toolchain, according to a CrowdStrike report. The worm spreads through code repositories with minimal detection, uses multi-day delays to evade telemetry, and can destroy compromised environments if it fails to spread. CrowdStrike has not identified the attacker's intent or origin, but senior vice president Adam Meyers said the malware is \"well thought-through\" and represents a growing trend in supply-chain attacks.", "body_md": "# Malware is targeting AI tools in software development environments\n\nMalware targeting AI coding assistants and software developers’ automated workflows is spreading into more environments with more capabilities, placing defenders at a growing disadvantage.\n\nA malware strain dubbed Sandworm_Mode, first [discovered by Socket](https://socket.dev/blog/sandworm-mode-npm-worm-ai-toolchain-poisoning) in February, represents a growing threat to software development. According to a CrowdStrike [report](https://www.crowdstrike.com/en-us/blog/denying-the-worm-sandworm-mode-and-ai-toolchain-supply-chain-attacks/), the self-propagating worm can spread through code repositories with minimal detection, raising alarms about software supply chains.\n\nThe malware’s capabilities are extensive, but not especially unique compared to the series of supply-chain worms known as [Shai-Hulud](https://cyberscoop.com/supply-chain-attack-shai-hulud-npm/), and more recently [Mini Shai-Hulud](https://cyberscoop.com/mini-shai-hulud-malware-npm-packages-compromised-again/).\n\n“This is the new trend,” Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told CyberScoop. “This is something we’re seeing more and more. It’s the new hotness right now.”\n\nSandworm_Mode targets and steals sensitive data, including credentials, keys and secrets that unlock paths to additional services and dependencies throughout the AI toolchain. This includes AI assistants, cloud providers, API keys for nine major LLM providers, CI/CD pipelines and automated systems that build, test and publish code.\n\nThese actions blend in with tens of thousands of other commands occurring daily in any given environment infused with AI development tools.\n\n“Trying to find the signal of something malicious happening is very difficult because there’s so much noise out there,” Meyers said.\n\nThe worm also paces itself, setting multi-day delays to separate initial access from follow-on malicious activity — creating a gap in victims’ telemetry windows, which makes it even more challenging for defenders to detect and attribute the chain of infection properly.\n\n“AI agents are pulling down all of these different dependencies continuously throughout the day,” Meyers said. “When you’re looking downrange from the perspective of the security operations team, you’re just seeing everybody pulling down these dependencies, and these dependencies self-unpacking and executing, so it just gets really, really noisy to try to find something bad happening.”\n\nThe malware covers its tracks further with a bit of a mean streak, by automatically destroying compromised environments if it can’t spread or accomplish its objectives.\n\n“It’s well thought-through, and well developed, so somebody spent some time caring and feeding this thing,” Meyer said.\n\nDespite CrowdStrike’s four-month review of Sandworm_Mode, the cybersecurity firm has yet to gain a firm handle on its intent, but Meyers said it is designed to attain a strong foothold, which could enable long-term access.\n\nCrowdStrike hasn’t determined who is responsible for the malware, yet Meyers said he doesn’t think TeamPCP, a threat group that’s been on a [rampage through open-source software this year](https://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/), is involved.\n\n“It could be a nation-state threat actor, or it could be an e-crime actor that’s looking to use this to then sell access to other organizations,” he said. “We don’t really know what the intention is.”\n\nThe state of Sandworm_Mode and whether it remains active is also unclear. CrowdStrike said it continues to observe recently active malicious supply-chain packages that follow similar but technically divergent patterns.\n\nUltimately, “the world has changed,” Meyers said, adding that many attackers are pursuing similar paths in the AI toolchain, requiring defenders and threat hunters to place a greater focus on this burgeoning mode of aggression.", "url": "https://wpnews.pro/news/malware-is-targeting-ai-tools-in-software-development-environments", "canonical_source": "https://cyberscoop.com/sandworm-mode-malware-ai-supply-chain-crowdstrike/", "published_at": "2026-07-22 17:24:46+00:00", "updated_at": "2026-07-22 17:27:00.964617+00:00", "lang": "en", "topics": ["ai-safety", "ai-infrastructure", "ai-tools"], "entities": ["Sandworm_Mode", "Socket", "CrowdStrike", "Adam Meyers", "TeamPCP", "Shai-Hulud", "Mini Shai-Hulud"], "alternates": {"html": "https://wpnews.pro/news/malware-is-targeting-ai-tools-in-software-development-environments", "markdown": "https://wpnews.pro/news/malware-is-targeting-ai-tools-in-software-development-environments.md", "text": "https://wpnews.pro/news/malware-is-targeting-ai-tools-in-software-development-environments.txt", "jsonld": "https://wpnews.pro/news/malware-is-targeting-ai-tools-in-software-development-environments.jsonld"}}