Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3840 articles · 177975 vulns · 37/41 feeds (7d)
← Back to list
EST
PRE-CVEEXPLOITED

SANDWORM_MODE npm Supply Chain Worm Campaign

60% confidence

Description

Multi-stage npm supply chain worm campaign discovered in February 2026 that targets AI-augmented development workflows. The attack exploits runtime behaviors of AI coding assistants, CI automation, and LLM toolchains through 19 malicious npm packages. The infection chain consists of three stages: an obfuscated loader with multi-layer encoding, initial reconnaissance with credential harvesting, and a full capability suite deployed after a time-delay gate.

Related News (1 articles)

Tier C
CrowdStrike Blog17h ago
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
PublishedJul 21, 2026
Last enriched4h ago
Tags
supply chain attacknpmmalwareai toolchainci/cdcredential harvestingobfuscationworm
Trending Score37
Source articles1
Independent1
Info Completeness4/14
Missing: cve_id, vendor, product, versions, cvss, epss, cwe, kev, patch, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 60%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Actively Exploited
Jul 21, 2026
Exploit Available
Jul 21, 2026