Socket's Threat Research Team has uncovered SANDWORM_MODE, an active npm supply chain worm campaign spanning at least 19 malicious packages published under two aliases. The worm uses typosquatting to impersonate popular Node.js utilities and AI coding tools (including Claude Code and OpenClaw), then executes a multi-stage

30m read timeFrom socket.dev
Post cover image
Table of contents
Threat Overview #Technical Analysis #Obfuscation and Anti-Analysis #Execution Flow #Public GitHub Action: ci-quality/code-quality-check #Mitigations, Defenses, and Prevention #Indicators of Compromise and Detection Artifacts #

Sort: