trade-press
Sandworm_Mode targets AI coding assistants and CI/CD pipelines
The compliance problem is not AI novelty; it is secret sprawl moving faster than review, logging and provenance can explain.
CyberScoop reports that CrowdStrike reviewed Sandworm_Mode, a self-propagating worm found by Socket in February, that targets AI coding assistants, LLM API keys, cloud credentials and CI/CD systems. Developers, DevOps teams and software suppliers face the operational exposure. The ugly part is familiar: the malware hides inside normal automated dependency activity, and CrowdStrike has not pinned down its operator, intent or current activity.