Malware is targeting AI tools in software development environments A self-propagating malware strain called Sandworm_Mode is targeting AI coding assistants and software development environments, stealing credentials, API keys, and secrets across the AI toolchain, according to a CrowdStrike report. The worm spreads through code repositories with minimal detection, uses multi-day delays to evade telemetry, and can destroy compromised environments if it fails to spread. CrowdStrike has not identified the attacker's intent or origin, but senior vice president Adam Meyers said the malware is "well thought-through" and represents a growing trend in supply-chain attacks. Malware is targeting AI tools in software development environments Malware targeting AI coding assistants and software developers’ automated workflows is spreading into more environments with more capabilities, placing defenders at a growing disadvantage. A malware strain dubbed Sandworm Mode, first discovered by Socket https://socket.dev/blog/sandworm-mode-npm-worm-ai-toolchain-poisoning in February, represents a growing threat to software development. According to a CrowdStrike report https://www.crowdstrike.com/en-us/blog/denying-the-worm-sandworm-mode-and-ai-toolchain-supply-chain-attacks/ , the self-propagating worm can spread through code repositories with minimal detection, raising alarms about software supply chains. The malware’s capabilities are extensive, but not especially unique compared to the series of supply-chain worms known as Shai-Hulud https://cyberscoop.com/supply-chain-attack-shai-hulud-npm/ , and more recently Mini Shai-Hulud https://cyberscoop.com/mini-shai-hulud-malware-npm-packages-compromised-again/ . “This is the new trend,” Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told CyberScoop. “This is something we’re seeing more and more. It’s the new hotness right now.” Sandworm Mode targets and steals sensitive data, including credentials, keys and secrets that unlock paths to additional services and dependencies throughout the AI toolchain. This includes AI assistants, cloud providers, API keys for nine major LLM providers, CI/CD pipelines and automated systems that build, test and publish code. These actions blend in with tens of thousands of other commands occurring daily in any given environment infused with AI development tools. “Trying to find the signal of something malicious happening is very difficult because there’s so much noise out there,” Meyers said. The worm also paces itself, setting multi-day delays to separate initial access from follow-on malicious activity — creating a gap in victims’ telemetry windows, which makes it even more challenging for defenders to detect and attribute the chain of infection properly. “AI agents are pulling down all of these different dependencies continuously throughout the day,” Meyers said. “When you’re looking downrange from the perspective of the security operations team, you’re just seeing everybody pulling down these dependencies, and these dependencies self-unpacking and executing, so it just gets really, really noisy to try to find something bad happening.” The malware covers its tracks further with a bit of a mean streak, by automatically destroying compromised environments if it can’t spread or accomplish its objectives. “It’s well thought-through, and well developed, so somebody spent some time caring and feeding this thing,” Meyer said. Despite CrowdStrike’s four-month review of Sandworm Mode, the cybersecurity firm has yet to gain a firm handle on its intent, but Meyers said it is designed to attain a strong foothold, which could enable long-term access. CrowdStrike hasn’t determined who is responsible for the malware, yet Meyers said he doesn’t think TeamPCP, a threat group that’s been on a rampage through open-source software this year https://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/ , is involved. “It could be a nation-state threat actor, or it could be an e-crime actor that’s looking to use this to then sell access to other organizations,” he said. “We don’t really know what the intention is.” The state of Sandworm Mode and whether it remains active is also unclear. CrowdStrike said it continues to observe recently active malicious supply-chain packages that follow similar but technically divergent patterns. Ultimately, “the world has changed,” Meyers said, adding that many attackers are pursuing similar paths in the AI toolchain, requiring defenders and threat hunters to place a greater focus on this burgeoning mode of aggression.