Home AIMalware targets AI tools in software development environments

Malware targets AI tools in software development environments

by OmarAli
Matt Kapko

Malware targeting AI coding assistants and automated software developer workflows is spreading into more and more feature-rich environments, putting defenders at an increasing disadvantage.

A malware strain called Sandworm_Mode, first discovered by Socket in February, poses a growing threat to software development. According to a CrowdStrike report, the self-propagating worm can spread through code repositories with minimal detection, raising alarms about software supply chains.

The malware’s capabilities are extensive, but not particularly unique compared to the series of supply chain worms known as Shai-Hulud and, more recently, Mini Shai-Hulud.

“This is the new trend,” Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told CyberScoop. “We’re seeing this more and more often. It’s the new trend at the moment.”

Sandworm_Mode targets and steals sensitive data, including credentials, keys and secrets that expose paths to additional services and dependencies across the AI ​​toolchain. This includes AI assistants, cloud providers, API keys for nine major LLM providers, CI/CD pipelines and automated systems that build, test and publish code.

These actions mix with tens of thousands of other commands that are executed daily in a given environment using AI development tools.

“Trying to find the signal that something malicious is happening is very difficult because there is so much noise out there,” Meyers said.

The worm also accelerates itself, imposing multi-day delays to separate initial access from subsequent malicious activity. This creates a gap in victims’ telemetry windows, making it even more difficult for defenders to properly detect and attribute the infection chain.

“AI agents continually break down all of these different dependencies throughout the day,” Meyers said. “If you look down from the security operations team perspective, you can just see how everyone is pulling down these dependencies and how these dependencies are unpacking and executing themselves, so it gets really, really loud when you try to detect something bad.”

The malware covers its tracks in a more mean way by automatically destroying compromised environments if it cannot spread or achieve its goals.

“It’s well thought out and well developed, so someone spent some time caring for and feeding this thing,” Meyer said.

Despite CrowdStrike’s four-month review of Sandworm_Mode, the cybersecurity company doesn’t yet have a firm grip on its intent, but Meyers said it’s designed to gain a strong foothold that could enable long-term access.

CrowdStrike has not determined who is responsible for the malware, but Meyers said he does not believe TeamPCP, a threat group that has been rampaging through open source software this year, was involved.

“It could be a nation-state threat actor, or it could be an electronic crime actor that wants to exploit this and then sell access to other organizations,” he said. “We don’t really know what the intent is.”

The status of Sandworm_Mode and whether it remains active is also unclear. CrowdStrike said it continues to monitor recently active malicious supply chain packages that follow similar but technically different patterns.

Ultimately, “the world has changed,” Meyers said, adding that many attackers are pursuing similar paths in the AI ​​toolchain, requiring defenders and threat hunters to focus more on this burgeoning type of aggression.

Matt Kapko

Table of Contents

Written by Matt Kapko

Matt Kapko is a reporter at CyberScoop. His responsibilities include cybercrime, ransomware, software bugs and vulnerability management. The lifelong Californian began his journalism career in 2001 with previous stints at Cybersecurity Dive, CIO, SDxCentral and RCR Wireless News. Matt holds degrees in journalism and history from Humboldt State University.

https://cyberscoop.com/sandworm-mode-malware-ai-supply-chain-crowdstrike/

Viral Trends

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More