Sandworm Mode npm Worm Supply Chain Attack
The Socket Research Team disclosed a sophisticated supply-chain malware campaign dubbed SANDWORM_MODE that uses typosquatted npm packages to infect developer environments and CI workflows. This worm-style attack harvests npm/GitHub tokens, environment secrets, and SSH keys, then exfiltrates them and propagates by modifying repositories and injecting malicious GitHub Actions. It also goes further by poisoning AI development toolchains through rogue MCP servers that manipulate AI coding assistants to expose additional credentials, highlighting an evolving threat targeting both traditional CI pipelines and AI-assisted workflows.
https://socket.dev/blog/sandworm-mode-npm-worm-ai-toolchain-poisoning
Comments
Post a Comment