SANDWORM_MODE is a sophisticated multi-stage npm supply chain worm that exploits the runtime behaviors of AI coding assistants, CI automation, and LLM toolchains. The worm uses multi-layer encoding to bypass static analysis, performs environment fingerprinting to differentiate developer workstations from CI runners, and deploys a rogue MCP server to compromise AI assistants into exfiltrating credentials. With propagation via stolen npm tokens, GitHub API tokens, and SSH fallback, plus a destructive dead switch, the campaign demonstrates a new class of supply chain attacks targeting the modern AI-driven development pipeline.
SANDWORMMODE
1 post
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks