www.darkreading.com 7/22/2026, 10:00:53 PM · external

Malware 'Sandworm_Mode' Hijacks Build Pipelines via NPM Packages

Malware 'Sandworm_Mode' Hijacks Build Pipelines via NPM Packages
CyberSIXT Evidence Panel
Primary Source socket.dev

THE article discusses emerging threats from attackers who exploit AI tools, exemplified by 'Sandworm_Mode', a malware that disguises malicious activities within legitimate AI coding environments. This worm spreads through malicious npm packages, hijacking continuous integration (CI) processes and compromising AI toolchains to steal sensitive credentials. CrowdStrike's analysis reveals that many of Sandworm_Mode's behaviors closely mimic normal development activities, complicating detection efforts.

As AI coding assistants become standard, defenders must enhance visibility and understanding of normal behaviors in these environments to distinguish between legitimate and malicious actions, addressing a new class of supply chain attacks.

View Primary Source Via www.darkreading.com

Article by CyberSIXT