SANDWORM_MODE: npm Supply Chain Worm Targeting CI and AI Toolchains
Автор: Phoenix Security
Загружено: 2026-02-26
Просмотров: 14
Описание:
SANDWORM_MODE is an active npm supply chain worm that executes on import, steals credentials, poisons CI workflows, and propagates across repositories.
00:00 — Introduction: What is SANDWORM_MODE
01:20 — Evolution from Shai-Hulud malware
02:10 — Three-stage execution breakdown
04:00 — AI toolchain poisoning & MCP injection
06:30 — Defense and remediation steps
This campaign weaponizes typosquatting, GitHub token abuse, workflow injection, and AI toolchain manipulation through rogue MCP server insertion.
If any of the affected package versions were installed, assume credential exposure and repository tampering.
Full technical write-up and IOCs:
https://phoenix.security/sandworm-mod...
#DevSecOps #ApplicationSecurity #SupplyChainSecurity #npm #GitHubActions #ASPM
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: