CrowdStrike Finds AI Development Worm That Steals Credentials and Destroys Files While Evading Detection

Cybersecurity firm CrowdStrike has identified a worm actively targeting AI software development infrastructure, capable of stealing access credentials, exfiltrating sensitive data, and triggering a destructive “death switch” to destroy files and lock out legitimate users. The findings were published in July 2026.

The worm operates in phases. It begins with reconnaissance of the target environment, then hunts for access tokens, cryptographic keys, and server credentials. As it gains privileges, it unpacks further capabilities and targets “npm” tokens — credentials that grant access to software package management servers and development functions such as pull requests. At its most deeply embedded, it can deploy its destructive payload, wiping files or blocking legitimate access entirely.

CrowdStrike has not yet attributed the worm to a specific threat actor, but Adam Meyers, the company’s senior vice president of counter adversary operations, said the activity fits patterns seen from groups including TeamPCP — which CrowdStrike tracks as “Altered Spider” — and North Korean actors targeting AI software supply chains.

What makes the worm particularly difficult to counter is how closely its behavior mirrors legitimate AI development automation. “It’s like a needle in a haystack, except this is a needle in a needle stack,” Meyers told WIRED. Security tools struggle to distinguish the worm’s activity from normal AI coding system operations because both produce similar telemetry signals. The worm’s authors compounded this by building in time delays, causing certain capabilities to execute hours or even days after initial infection, making it harder for defenders to trace cause and effect.

Meyers noted that AI coding pipelines reduce the available data points that security scanners traditionally rely on, shrinking the detection surface further. He called for broader industry collaboration on structural solutions, warning that as AI-driven software development expands, supply chain threats are evolving to exploit the trust relationships built into those systems.

Source: WIRED

This article was generated by AI and cites original sources.
Scroll to Top