The SANDWORM_MODE campaign is a multi-stage npm supply chain worm that targets AI-augmented development workflows by exploiting runtime behaviors of AI coding assistants and CI/CD pipelines, leading to credential theft, supply chain poisoning, and persistence through obfuscated loaders, credential harvesting, and malicious Git hooks.
PoC
npm +27
supply-chain-attack
git
ai-toolchain
development-workflow
code-injection
credential-theft
persistence
evasion
3r
14t
8i
updated