READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

New Malware Strain Hides Inside AI Coding Tools to Steal Credentials and Sabotage Systems

New Malware Strain Hides Inside AI Coding Tools to Steal Credentials and Sabotage Systems
CrowdStrike researchers found a worm burrowing into AI development pipelines, stealing access tokens and cryptographic keys while disguising itself as normal AI automation. The malware can trigger a destructive "death switch" that wipes files and locks out legitimate users. Nobody's been named as the culprit yet, and that's the scary part.

Cybersecurity firm CrowdStrike says it found a new type of malware built specifically to exploit the blind spots created by AI coding tools, according to Wired. The worm doesn't just steal data. It can also destroy it.

Adam Meyers, CrowdStrike's senior vice president of counter adversary operations, told Wired the company hasn't tied the campaign to a specific hacking group yet. But he said it fits a pattern CrowdStrike is tracking across multiple threat actors, including a group CrowdStrike calls "Altered Spider" (also known as TeamPCP) and North Korean state-linked hackers, all of whom are increasingly targeting AI software supply chains.

"For the first time we're experiencing how much AI and the AI toolchain has played into the broader tech ecosystem," Meyers said.

How the Worm Operates

The malware works in stages, according to CrowdStrike's research as reported by Wired. It starts with reconnaissance, mapping out the target environment. Then it hunts for access tokens, cryptographic keys, and server credentials it can hand off to attackers.

A key target is npm tokens, the access credentials tied to widely used software package management servers that developers rely on to build and ship code. Once the malware grabs those, it can reach deeper into an organization's development pipeline, including pull request systems.

The deeper it gets, the more it can steal. Once it's dug in far enough, it can activate what Meyers calls a "death switch," a capability to destroy files or lock legitimate users out of systems they need to run their own infrastructure.

Why It's Hard to Catch

The most striking part of CrowdStrike's findings isn't what the malware does. It's how well it hides.

Much of the worm's activity looks identical to normal AI coding automation, the kind of legitimate background processes that companies now run constantly as AI tools get embedded into everyday software development. Meyers described it to Wired as "a needle in a needle stack."

"This looks very much like a lot of the automation organizations are using to build code, so it's very difficult to detect," Meyers said.

That creates a challenge for security teams. Traditional detection tools work by spotting behavior that deviates from a baseline of normal activity. But when AI agents are constantly reading files, requesting credentials, and making automated changes as part of their normal job, there's no clean baseline left. Meyers put it bluntly: there's "a lot of telemetry overlap because legitimate AI coding systems are operating the same way as this worm."

CrowdStrike is an interested party here, since flagging new threat classes is part of its business model. But the underlying technical claim, that AI-driven automation traffic looks a lot like malicious automation traffic, reflects a structural observation about how these systems are built. Anyone who has watched how quickly companies bolted AI coding assistants onto existing pipelines, often without rebuilding the security architecture around them, would recognize the concern: speed of adoption outpaced the tooling meant to keep it safe.

What's Still Unknown

CrowdStrike has not publicly attributed this specific worm to a named group, and no company or government agency has confirmed it was breached by this exact malware. This is a discovered capability, not yet a confirmed large-scale attack with named victims.

CrowdStrike says the technique fits a broader trend it's tracking among groups like Altered Spider and North Korean actors. That's CrowdStrike's assessment based on its own threat intelligence, not an independently verified link between this specific worm and those specific groups.

The broader context matters too. TechCrunch reported this week that Treasury Secretary Scott Bessent said the U.S. could sanction Chinese open AI models over alleged intellectual property theft, part of the Trump administration's ongoing effort to slow China's AI progress. That's a separate track of the AI security fight, focused on model theft and export controls rather than credential-stealing malware, but it underscores how much of the current AI arms race is playing out on the security and geopolitical front simultaneously.

For now, CrowdStrike's advice to organizations running AI coding pipelines is straightforward: audit access tokens regularly, monitor npm and package management credentials closely, and don't assume AI automation traffic is inherently safe just because it looks routine. Companies will need to act quickly on this advice, given how new and disorienting the AI-assisted development stack still is for most security teams.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredA Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
center-left
WiredA Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
unknown
aitopicsUnited States - AITopics: New Malware Targeting AI
unknown
werindiaWeRIndia - Science and Technology News