Home / Companies / Socket / Blog / Post Details
Content Deep Dive

SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
7,183
Company Posts That Month
33
Language
English
Hacker News Points
-
Post removed?
No
Summary

An active supply chain attack, reminiscent of the Shai-Hulud worm, has been identified by Socket’s Threat Research Team, involving at least 19 malicious npm packages and two npm aliases. Dubbed "SANDWORM_MODE," this campaign utilizes typosquatting and AI toolchain poisoning, targeting high-traffic developer utilities and AI coding tools. The malware employs GitHub API exfiltration with DNS fallback, automated propagation using stolen identities, and a multi-layered execution strategy, embedding malicious MCP servers into AI assistant configurations. It harvests credentials, crypto keys, and CI secrets for exfiltration, deploying a Shai-Hulud-style dead switch that wipes home directories under certain conditions. Despite the destructive routines being disabled in this iteration, the worm poses a significant risk, with propagation mechanisms exploiting npm and GitHub infrastructure. The campaign reflects ongoing threat actor adaptation, leveraging AI tool interference and polymorphic capabilities for future iterations, prompting immediate defensive measures from npm, GitHub, and Cloudflare to mitigate risks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 25 1,388 209 84 +19%
MCP 16 3,346 363 139 +19%
LLM 9 5,138 781 181 +34%
AI Coding Assistant 7 1,009 253 106 +42%
AI Agents 1 3,583 743 199 -1%
OpenClaw 1 1,172 87 30 +176%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.