344
Productivity & Workflow355
Automation & Workflow224
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps174
Writing & Content Creation203
Data & Analytics141
Design & Creative170
Photography & Imaging156
Customer Support131
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
CrowdStrike reports a worm that hides in AI coding pipelines to steal logins and data and can also destroy files after delays.
In short: Security researchers say they found a worm that targets the AI tools and services companies use to build software, stealing logins and sometimes destroying files.
CrowdStrike researchers say they discovered a “worm” in the wild while investigating attacks on the AI software supply chain. A worm is malware that can spread and dig deeper once it gets into a system, like a leak that moves from one room to the next.
The worm works in phases, according to CrowdStrike. It first checks what kind of systems it has landed in. Then it hunts for access tokens, cryptographic keys, and other credentials, which are like digital keys that let someone sign in to services and servers.
One specific target is “npm” tokens. npm is a common service used to download and manage code packages (like an app store, but for building blocks of software). With these tokens, attackers may be able to get into development systems, pull code, or make changes.
CrowdStrike says the worm can also trigger a destructive “death switch.” That could destroy files or block real users from accessing the compromised infrastructure. CrowdStrike has not linked the campaign to a specific group, but says it fits a broader pattern of attacks that target the tools developers rely on.
A key problem is that the worm can hide in “blind spots.” Its actions can look like normal automated work inside modern AI coding pipelines. It can also wait hours or days before running certain steps, which makes it harder to connect cause and effect.
As more companies use AI helpers to write and manage code, security teams may have a harder time telling normal activity from an attack. CrowdStrike says the industry will likely need better ways to monitor these pipelines and more cooperation across companies to spot suspicious behavior earlier.
Source: Wired