Jul 21, 2026
ManyPress

Advertisement

Technology

Cybersecurity researchers have discovered a worm that exploits AI development tools to steal credentials and destroy data by mimicking legitimate automation processes.

ManyPress

ManyPress

ManyPress Editorial

2 min readSource:Wired
CrowdStrike Identifies New Worm Targeting AI Software Supply Chains

Key facts

  • CrowdStrike identified the worm while investigating attacks on the AI software supply chain.
  • The malware targets sensitive data including cryptographic keys and npm access tokens.
  • A 'death switch' feature allows the worm to destroy files or block access to compromised infrastructure.
  • The worm uses time delays to execute actions hours or days apart, making it difficult for defenders to trace events.
  • Adam Meyers, CrowdStrike's senior vice president of counter adversary work, described the threat as an emerging attack class.

CrowdStrike researchers have identified a new worm targeting the AI software supply chain. The malware is designed to steal access credentials, exfiltrate sensitive data, and destroy files within development environments. While the specific origin of the worm remains unattributed, experts note that its behavior aligns with evolving tactics used by groups targeting AI infrastructure to exploit trust relationships in modern software development.

How the Worm Operates

The malware functions in distinct phases, beginning with reconnaissance to evaluate the target environment. It specifically hunts for cryptographic keys, server access credentials, and access tokens. As the worm gains higher privileges, it targets 'npm' tokens, which provide attackers with control over software package management servers and development capabilities like pull requests. Once deep within a system, the worm can deploy a 'death switch' to block access to infrastructure or destroy files.

Evasion and Detection Challenges

A primary concern for security teams is the worm's ability to operate within blind spots by mimicking the behavior of legitimate AI coding automation. Because the malware's actions overlap with standard development telemetry, traditional security scanners struggle to distinguish between authorized activity and malicious intent. To further complicate detection, the worm incorporates time delays, executing its capabilities hours or days after initial deployment to obscure the link between cause and effect.

Advertisement

This article was independently rewritten by ManyPress editorial AI from reporting originally published by Wired.

Technology