SANDWORM_MODE is a self-propagating npm supply-chain worm targeting software developers, CI/CD environments, source-code repositories, cloud-linked development workflows, and AI coding assistants. It has been associated with malicious npm packages used to compromise developer systems and automated build pipelines, then harvest credentials and other secrets including npm and GitHub tokens, cloud-access material, cryptocurrency-related secrets, and API keys for multiple LLM providers. The malware has also been observed targeting AI assistant ecosystems by injecting a rogue MCP server and using prompt-injection techniques to coerce supported coding assistants into collecting sensitive local context and credentials for attacker access.
The malware operates as a multi-stage campaign. An initial stage rapidly steals accessible secrets and exfiltrates them, while a later stage activates after a delay of roughly 48 to 96 hours on developer workstations, or immediately in CI environments. This delayed execution is designed to reduce correlation between package installation and subsequent malicious behavior. SANDWORM_MODE propagates by abusing stolen npm and GitHub credentials to publish additional malicious packages and infect repositories, and it has been reported to tamper with dependencies, workflows, and repository automation to extend compromise. Persistence has been observed through git-hook mechanisms, enabling continued execution within developer workflows.
A notable characteristic of SANDWORM_MODE is its effort to blend into legitimate development activity. Its command execution, file access, configuration changes, repository interaction, and API usage can resemble normal AI-assisted coding and CI/CD operations, complicating detection. Reported exfiltration methods include multiple channels, and the malware has been described as capable of poisoning CI pipelines and establishing a durable foothold for follow-on access. Attribution remains unresolved, and available reporting has characterized it as an emerging but significant example of malware designed to exploit trusted software supply chains and AI-augmented development environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
An active Shai-Hulud-like supply chain worm campaign spreads via typosquatting and AI toolchain poisoning, across at least 19 malicious npm packages... One representative example, suport-color@1.0.1, impersonates supports-color... Other packages in the set follow the same look-alike branding strategy to increase the likelihood of accidental installation.
Sandworm_Mode also compromises AI assistants such as Cursor and Claude Code via a rogue MCP server that uses prompt injection to trick them into silently reading and passing credentials to the attacker.
Through GitHub API tokens, it enumerates accessible repositories, injects a carrier dependency, commits or opens a pull request...
One early manifestation of the emerging threat is Sandworm_Mode, a self-propagating worm that spreads through malicious npm packages.
The Sandworm_Mode campaign spread through 19 malicious npm packages and exploited the normal runtime behaviors of AI coding assistants, CI automation, and LLM toolchains that organizations are increasingly deploying in their development pipelines.
Sandworm_Mode also compromises AI assistants such as Cursor and Claude Code via a rogue MCP server that uses prompt injection to trick them into silently reading and passing credentials to the attacker.
Through GitHub API tokens, it enumerates accessible repositories, injects a carrier dependency, commits or opens a pull request...
The initial payload employs multi-layer encoding via Base64 decode, zlib inflate, XOR decryption, and indirect eval() or Module._compile() calls, which are triggered on package import.
The malware covers its tracks further ... by automatically destroying compromised environments if it can’t spread or accomplish its objectives.
After the gate clears, AES-256-GCM decryption unpacks the full payload into /dev/shm, executes it via require(), then immediately unlinks the file.
Sandworm_Mode also compromises AI assistants such as Cursor and Claude Code via a rogue MCP server that uses prompt injection to trick them into silently reading and passing credentials to the attacker.
Sandworm_Mode features a 48- to 96-hour delay between when a malicious package is installed and when its full payload activates.
This includes AI assistants, cloud providers, API keys for nine major LLM providers, CI/CD pipelines and automated systems that build, test and publish code.
Independent of this action, the worm harvests API keys for nine LLM providers ... from environment variables and .env files.
Fingerprinting the runtime environment to determine if execution is on a developer workstation or CI runner.
Sandworm_Mode executed commands, accessed files, modified configurations, interacted with repositories, and called APIs in ways that closely resembled the normal behavior of AI assistants, CI/CD systems, and other development tools.
The worm is designed to steal npm, GitHub, cloud, cryptocurrency, and LLM-provider credentials, and exfiltrate them across three channels, including DNS tunneling.
Harvested cryptocurrency keys are immediately sent in an HTTP POST request to an attacker-controlled Cloudflare Worker endpoint... data is first POST'd over HTTPS to attacker infrastructure, then mirrored to attacker-controlled GitHub private repositories for redundancy
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A self-propagating supply-chain worm targeting AI coding assistants and developers’ automated workflows. It spreads through code repositories with minimal detection, steals credentials, keys and secrets across AI assistants, cloud providers, LLM APIs and CI/CD systems, uses multi-day delays to evade telemetry correlation, and can automatically destroy compromised environments if it cannot spread or achieve its objectives.
A self-propagating worm spread via malicious npm packages that hijacks CI workflows and poisons AI toolchains. It steals npm, GitHub, cloud, cryptocurrency, and LLM-provider credentials; exfiltrates them via multiple channels including DNS tunneling; propagates by infecting packages and repositories; establishes persistence through Git hooks; and compromises AI assistants such as Cursor and Claude Code via a rogue MCP server using prompt injection.
An npm supply-chain, self-propagating info-stealing worm distributed via typosquatted npm packages. It runs in two stages: Stage 1 rapidly harvests and exfiltrates npm/GitHub tokens and crypto keys; Stage 2 (48–96 hours later or immediately in CI) expands theft to password managers, local SQLite stores/files, and LLM API keys, and injects a malicious MCP server with prompt-injection tool descriptions to coerce AI coding assistants into collecting and leaking credentials. It propagates by using stolen npm/GitHub tokens to publish malicious packages and inject into GitHub repos, and uses git hook-based persistence.
Multi-stage npm supply-chain worm that executes on import, steals developer/CI/cloud/crypto/LLM credentials, poisons GitHub Actions workflows and release tooling, persists via global git hooks, propagates by injecting dependencies and patching lockfiles, and tampers with AI coding assistants via rogue MCP server injection to exfiltrate secrets (e.g., SSH keys, AWS creds).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.