Skip to main content
Emerging ThreatsMalware & Ransomware

Malware Targets AI Tools in Software Development Environments

Developer workstation with laptop and monitor displaying code, surrounded by notes and sticky notes in a modern office…
“This is the new trend,” Adam Meyers told CyberScoop, summing up a wave of malware that now aims squarely at the tools developers use to build and deploy software.

Sandworm_Mode: a supply-chain worm aimed at the AI toolchain

First discovered by Socket in February and described in a CrowdStrike report, Sandworm_Mode is a self‑propagating worm that spreads through code repositories and targets the modern AI development stack. CrowdStrike found it can steal credentials, keys and other secrets that "unlock paths to additional services and dependencies throughout the AI toolchain," including AI assistants, cloud providers, and API keys for nine major LLM providers. The worm also seeks access to CI/CD pipelines and the automated systems that build, test and publish code.

Capabilities that exploit everyday developer workflows

Sandworm_Mode leverages the constant churn of modern development environments. According to CrowdStrike, the malware’s actions can blend in with "tens of thousands of other commands occurring daily in any given environment infused with AI development tools." It automatically pulls down and executes dependencies — activity that, in noisy environments, resembles legitimate developer behavior and complicates detection.

Techniques crafted to avoid detection and persist

CrowdStrike’s analysis highlights multiple evasion techniques. Sandworm_Mode paces itself, inserting multi‑day delays that separate initial access from follow‑on malicious activity and create gaps in telemetry windows that defenders rely on to link events. The worm also self‑unpacks and executes dependencies, increasing the ambient noise defenders must sift through. When it cannot spread or meet its objectives, the malware has a destructive mode that can automatically destroy compromised environments. CrowdStrike described the strain as "well thought‑through, and well developed," evidence, in their view, that "somebody spent some time caring and feeding this thing."

Where Sandworm_Mode sits among supply‑chain worms

CrowdStrike compared Sandworm_Mode to an earlier series of supply‑chain worms known as Shai‑Hulud and the more recent Mini Shai‑Hulud. While CrowdStrike said Sandworm_Mode’s capabilities are extensive, they are "not especially unique" compared with those prior strains. The firm also reported observing recently active malicious supply‑chain packages that follow similar but technically divergent patterns, suggesting the tactic has proliferated across multiple actors and code ecosystems.

What this means for technologists, policymakers, and adversaries

  • Technologists and security teams: defenders will face increased noise in AI‑infused development environments as malicious dependencies and automated agents appear alongside legitimate tooling. CrowdStrike’s four‑month review underscores the difficulty of attributing chains of infection when malicious actions are paced and buried in normal developer traffic.
  • Policymakers and regulators: the unclear intent and provenance of Sandworm_Mode complicate public‑policy responses. CrowdStrike has not determined who is responsible, and its analysts said they do not believe TeamPCP — a group "that’s been on a rampage through open‑source software this year" — is involved. CrowdStrike said the author could be a nation‑state actor or an e‑crime actor selling access, but the firm "doesn’t really know what the intention is."
  • Adversaries and threat actors: the malware demonstrates a clear incentive to weaponize developer workflows and AI toolchains. CrowdStrike reported that attackers are pursuing similar paths, and that the "world has changed" as those avenues become more attractive and more prevalent.

CrowdStrike continues to monitor Sandworm_Mode and related malicious packages, but the firm has not yet pinned down intent or attribution after four months of analysis. The combination of broad capability, the ability to hide in the routine activity of AI‑driven development, and destructive fallback behavior creates a difficult landscape for defenders and raises a simple operational question: if the binaries and packages that put code together can themselves be weaponized, how do defenders tell the difference between dependency and danger?

Read the original CrowdStrike and CyberScoop coverage: https://cyberscoop.com/sandworm-mode-malware-ai-supply-chain-crowdstrike/