AI Safety 🇺🇸 24.07.2026 06:02

Stealthy Hacker Tool Targeting AI Infrastructure Hides in Victims' Blind Spots

CrowdStrikeCrowdStrike
CrowdStrike researchers discovered a worm attacking the AI software supply chain. The malware steals credentials, gains access to systems, and destroys files, masquerading as legitimate AI agent activities, making detection extremely difficult.
CrowdStrike has discovered a network worm that attacks the supply chain of AI software. Attackers use it to steal access tokens, cryptographic keys, and server credentials, as well as to destroy files and block access to compromised infrastructure. The worm operates in multiple stages: first it conducts reconnaissance, then searches for sensitive data, including npm tokens that provide access to package management servers. After gaining privileges, it deploys a "kill switch" to destroy data. The main challenge in detection is that the worm's activity is almost indistinguishable from legitimate actions of AI agents developing code, and telemetry is overloaded due to pattern matching. Additionally, built-in execution delays (ranging from hours to days) make it difficult to establish causal links. CrowdStrike does not attribute the worm to a specific group, but notes that it fits into the evolution of attacks on AI infrastructure by groups such as TeamPCP (Altered Spider) and North Korean hackers.
Source: Wired AI — original
Our earlier posts on this topic ↓
Fresh news