Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.
July 22, 2026
Attackers are beginning to hide malicious activity inside trusted AI coding assistants and CI pipelines, mimicking routine developer and automation behavior so closely that some attack techniques can evade current detection tools entirely.
One early manifestation of the emerging threat is Sandworm_Mode, a self-propagating worm that spreads through malicious npm packages. Researchers at Socket Security who discovered the threat earlier this year have described it as a Shai-Hulud-style worm that hijacks CI workflows and poisons AI toolchains.
CrowdStrike subsequently analyzed Sandworm_Mode's known behaviors to identify the ones the company could detect using existing telemetry and to see how many new detection rules it could develop for the malware. CrowdStrike's findings, detailed in a report this week, offer a sobering picture of the challenges organizations will face as attackers increasingly abuse the AI toolchain in a manner similar to living off the land attacks.








