CrowdStrike uncovers sophisticated worm targeting AI software supply chains
New research from CrowdStrike reveals a worm in the wild exploiting trust relationships in AI development pipelines, with tactics aligning with groups such as TeamPCP and North Korean actors.

CrowdStrike researchers have identified a new worm actively targeting AI coding systems and software supply chains, exploiting the growing reliance on artificial intelligence in global software development. The malware conducts reconnaissance, steals access credentials including npm tokens and cryptographic keys, and can deploy a "death switch" to destroy files or block legitimate access to compromised infrastructure.
The threat presents a significant detection challenge because its behaviour closely mimics legitimate AI automation, creating substantial telemetry overlap. Adam Meyers, CrowdStrike's senior vice president of counter adversary work, described the difficulty of distinguishing malicious activity from standard development processes as finding "a needle in a needle stack." He noted that as AI coding agents become the development standard, supply chain threats are evolving to exploit these trust relationships.
The worm operates in distinct phases, beginning with reconnaissance to assess the target environment. It then seeks out access tokens and sensitive data, particularly npm tokens that provide access to key software package management servers. As the malware gains privileges, it unpacks itself further to exfiltrate additional credentials, including server access details and pull request capabilities.
To evade detection, the malware includes time delays where various capabilities execute hours or even days after the initial groundwork is laid. This obscures the cause-and-effect relationship between the initial compromise and subsequent destructive actions, making it harder for defenders to establish a clear timeline of events.
While CrowdStrike has not attributed the activity to a specific actor, the tactics align with those used by groups including TeamPCP, tracked by the firm as "Altered Spider", and North Korean actors. Meyers characterised the campaign as an emerging attack class, highlighting how attackers are leveraging the broader tech ecosystem's integration of AI tools.
Traditional security scanners and analysis tools struggle to detect this threat due to the lack of distinct telemetry signals. Meyers emphasised that the limited detection surface makes it extremely onerous to determine legitimate versus illegitimate behaviour, calling for collaboration across the industry to develop structural solutions.
CrowdStrike is currently working on strategies to connect more of the dots regarding these attacks. However, the firm warns that as AI software development continues to explode, the need for coordinated efforts to address these evolving supply chain risks is becoming increasingly pressing.
