Attackers are beginning to hide malicious activity inside trusted AI coding assistants and CI pipelines, mimicking routine developer and automation behavior so closely that some attack techniques can evade current detection tools entirely. One early manifestation of the emerging threat is Sandworm_Mode, a self-propagating worm that spreads through malicious npm packages. Researchers at Socket Security who discovered the threat earlier this year have described it as a Shai-Hulud-style worm that
sandworm_mode (2)
Security researchers have uncovered a new supply chain attack targeting the NPM registry with malicious code that exhibits worm-like propagation capabilities. Named Sandworm_Mode, the attack was deployed through 19 packages published under two aliases, which relied on typo squatting to trick developers into executing the malicious code. According to cybersecurity firm Socket, the attack bears the hallmarks of the Shai-Hulud campaign that hit roughly 800 NPM packages in September and November 2