AI SafetyResearch 🇺🇸 24.07.2026 06:02

Hidden Worm Targeting AI Infrastructure Hides in Victims' Blind Spots

CrowdStrikeCrowdStrike
CrowdStrike researchers discovered a worm that targets AI software supply chains, stealing credentials and destroying data while mimicking legitimate actions. The malware exploits blind spots in AI development pipelines, making detection extremely difficult due to telemetry overlap.
Cybersecurity firm CrowdStrike identified a worm actively targeting AI infrastructure during an investigation of AI software supply chain attacks. The malware operates in phases, starting with reconnaissance, then stealing access tokens, cryptographic keys, and npm tokens to gain deeper access. It can ultimately deploy a 'death switch' to destroy files or block legitimate access. The worm's activity closely mimics legitimate automation used in code development, creating a 'needle in a needle stack' detection challenge. Attackers include time delays of hours or days to further evade detection. CrowdStrike has not attributed the activity to a specific actor but notes it fits broader trends seen with groups like TeamPCP and North Korean actors targeting the AI supply chain. The company emphasizes the need for structural solutions as AI coding agents become standard.
Сокращения
npm = Node Package Manager — менеджер пакетов Node
Source: Wired AI — original
Our earlier posts on this topic ↓
Fresh news