SANDWORM_MODE npm supply chain worm hijacks AI coding assistants MCP server credential theft
Development teams using AI coding assistants are now inside a supply-chain attack's blast radius. CrowdStrike $CRWD is tracking SANDWORM_MODE, a self-spreading npm worm that steals cloud credentials and SSH keys, then plants a rogue MCP server to hijack AI coding tools and leak t
Security researchers at CrowdStrike $CRWD are tracking a new strain of supply-chain attack called SANDWORM_MODE that specifically targets AI-assisted software development. The worm was first identified by Socket's threat research team and spreads through typosquatted npm packages, self-propagating across developer machines and CI/CD pipelines on macOS, Linux and Windows. Once installed, it harvests npm tokens, cloud credentials, SSH keys and environment variables, then hijacks GitHub repositories by injecting malicious GitHub Actions workflows and modifying lockfiles to keep spreading. What distinguishes SANDWORM_MODE from earlier npm worms is its focus on AI development tools. It installs a hidden rogue MCP (Model Context Protocol) server and registers it with AI coding assistants running on the infected machine, then uses prompt injection and configuration tampering to manipulate those assistants into silently exposing additional credentials, including API keys for large language model providers. The attack shows that as companies wire AI coding assistants directly into their development pipelines, those assistants become a new credential-theft surface that traditional endpoint security was not built to watch. Any organization that has not audited what its AI coding tools can read and write inside a CI/CD environment is exposed to this class of attack.