Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
A sophisticated multi-stage npm supply chain worm called SANDWORM_MODE was discovered in early 2026, targeting AI-augmented development environments like GitHub Copilot and Cursor. The worm exploits integrations between …