TI Mindmap HUB
Threat Intelligence Report

SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains

๐Ÿ“… February 21, 2026 ๐Ÿ“ฐ socket.dev ๐Ÿ” 0 CVE(s) referenced

A sophisticated npm supply chain worm, SANDWORM_MODE, is actively hijacking CI workflows, stealing secrets, and poisoning AI developer toolchains via typosquatted packages and weaponized GitHub Actions, enabling automated propagation, credential exfiltration, and persistent compromise across both developer and CI environments.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle