Find notable cyber news and cases, enriched with sources, timelines, and signals.

SANDWORM_MODE supply-chain worm targeting AI assistant configs

Malware Activity
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

The SANDWORM_MODE worm is spreading through malicious npm packages, stealing developer and CI credentials and injecting rogue MCP servers into AI assistant configurations. It also harvests API keys for multiple large language model providers, widening the blast radius beyond software dependencies. The operation uses typosquatting, compromised npm/GitHub accounts, and staged payloads to reach developers and CI environments. Anyone who installed affected packages faces secret theft, repository tampering, and downstream account compromise risk.

Related Happenings

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

GitHub API enumeration campaign targeting corporate organizations

Campaign
H score17 First: 09.07.2026 21:38 Last: 09.07.2026 21:38 Sources 1

About this happening: A GitHub API reconnaissance campaign is systematically mapping corporate organizations, repositories, and user accounts across multiple companies, expanding the risk of fo...

Malicious npm and PyPI payment SDK typosquat packages

Malware Activity
H score40 First: 09.07.2026 18:09 Last: 09.07.2026 18:09 Sources 1

About this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...

Malicious npm and PyPI Paysafe, Skrill, and Neteller SDK packages delivering stealer malware

Malware Activity
H score37 First: 08.07.2026 22:54 Last: 08.07.2026 22:54 Sources 1

About this happening: Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs delivered stealer malware that siphoned secrets from developer environment...

Timeline

  1. 23.02.2026 18:00 2 articles · 4mo ago

    SANDWORM_MODE supply-chain worm disclosed

    Initial Disclosure

    Socket's Threat Research Team disclosed SANDWORM_MODE as a Shai-Hulud-like supply-chain worm spreading through at least 19 malicious npm packages published under the aliases official334 and javaorg. The malware used typosquatting and a concealed multi-stage payload to steal developer and CI credentials, inject rogue MCP servers into AI assistant configurations such as Claude Desktop, Cursor, VS Code Continue and Windsurf, and harvest API keys for nine large language model providers. Socket also said it notified npm, GitHub and Cloudflare, and that Cloudflare disabled associated infrastructure, npm removed the malicious packages, and GitHub dismantled related repositories.

    Show sources