A new type of malware has been discovered actively targeting artificial intelligence (AI) development infrastructure, capable of stealing credentials, exfiltrating sensitive data, and even destroying files. Cybersecurity firm CrowdStrike identified the worm in the wild during investigations into AI software supply chain attacks.
The malware operates in multiple phases, initially performing reconnaissance to map the target environment. It then seeks out access tokens, cryptographic keys, and server access credentials for exfiltration. As it gains deeper privileges, it unpacks further, specifically targeting npm tokens which grant access to critical software package management servers and development capabilities such, as pull requests.
A significant concern is the malware's destructive capability, which CrowdStrike researchers have termed a "death switch." This functionality allows the attackers to destroy files or block legitimate users from accessing the compromised infrastructure.
According to CrowdStrike, a key challenge in detecting this worm is its ability to mimic legitimate AI automation activities. Much of its malicious behavior occurs within blind spots, making it difficult for traditional security scanners and analysis tools to differentiate between legitimate and malicious actions. The telemetry generated by the worm often overlaps with that of legitimate AI coding systems, complicating detection efforts.
To further evade detection, the malware incorporates time delays, with various capabilities executing hours or even days after the initial compromise. This tactic makes it harder for defenders to establish a clear chain of events leading to a breach.
CrowdStrike has not yet attributed the activity to a specific threat actor, but notes that it aligns with broader trends observed in AI software supply chain attacks by groups like TeamPCP (tracked by CrowdStrike as "Altered Spider") and North Korean state-sponsored actors. The firm emphasizes that this campaign represents an emerging class of attacks exploiting the trust relationships inherent in AI coding agents, which are becoming standard in software development.
Researchers highlight the urgent need for collaboration across the industry to develop structural solutions, as the limited detection surface and telemetry overlap make it extremely challenging to distinguish legitimate from illegitimate behavior within AI development pipelines.






