SANDWORM_MODE and the Rise of AI Toolchain Supply Chain Attacks
2026-07-23
In February 2026, Socket.dev published research on a multi-stage npm supply chain worm operating under the internal flag SANDWORM_MODE. The campaign spanned 19 malicious packages in total across two unique publisher aliases and demonstrated a new class of supply chain attacks that targeted AI-augmented development workflows.Read More…











