Security · 2h ago
SANDWORM_MODE Malware Targets AI Coding Assistants in Novel Supply Chain Attack
A sophisticated npm worm named SANDWORM_MODE exploits AI coding assistants like GitHub Copilot and Cursor to infiltrate development environments. It operates in three stages, harvesting credentials and deploying rogue MCP servers. The attack highlights a new class of supply chain threats targeting AI toolchains.
Meridian48 take
The worm's use of AI assistant integrations as an attack vector underscores a growing blind spot in software supply chain security.
Read the full reporting
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks →
DEV Community
supply-chain-attackai-security