Tech Current

Hackers are targeting AI toolchains, not just AI apps

WIRED, citing CrowdStrike research, says attackers are aiming at the software pipelines behind AI development to steal credentials, exfiltrate data, and in some cases sabotage systems.

Published by Tech Current · Publisher Alex Naz
Hackers are targeting AI toolchains, not just AI apps
AI-assisted editorial illustration for this article.

Key Takeaways

  • CrowdStrike says attackers are increasingly targeting AI software supply chains and development pipelines.
  • The malware described can steal credentials, gather sensitive data, and use destructive functions against compromised systems.
  • Because the activity resembles legitimate AI automation, defenders may have a harder time detecting it.

What happened

WIRED reports on new research from CrowdStrike showing malware aimed at the AI toolchain itself. Rather than focusing only on the applications built with AI, the activity appears designed to slip into the systems that support AI development and software delivery.

According to the report, researchers found a worm in the wild while investigating AI software supply chain attacks. CrowdStrike says it has not attributed the activity to a specific actor, but the company sees it as part of a broader trend in which attackers are targeting the AI software supply chain.

Adam Meyers, CrowdStrike’s senior vice president of counter adversary work, told WIRED that the campaign reflects an emerging attack class. He said that as AI coding agents become a normal part of development, supply chain threats are evolving to exploit the trust relationships those systems depend on.

The worm works in phases. First, it performs reconnaissance to understand the target environment. Then it searches for access tokens and other sensitive data, including cryptographic keys and server access credentials. As it gains more privileges, it keeps extracting credentials and can also collect “npm” tokens that provide access to package management servers and development functions such as pull requests.

CrowdStrike says the deeper the malware moves into a system, the more sensitive data it can reach. At that stage, it can also use a destructive capability Meyers described as a “death switch” that can destroy files or block legitimate access to compromised infrastructure.

Why it matters

The most important part of this story is not only that attackers are stealing credentials or exfiltrating data. It is that they are doing so in a part of the stack that may blend in with normal AI development activity.

Meyers told WIRED that much of the worm’s behavior takes place in blind spots because it looks similar to legitimate automation. That creates a detection problem for security teams. If AI coding systems and malicious tools are both interacting with the environment in similar ways, traditional security telemetry may not clearly separate normal behavior from abuse.

Illustration for Hackers are targeting AI toolchains, not just AI apps
AI-assisted editorial illustration for this article.

CrowdStrike says this is especially difficult in AI software development pipelines because the usual signals security teams depend on may be limited or ambiguous. In the company’s telling, legitimate AI coding systems can generate the same kinds of telemetry as the worm, making it hard to tell what is allowed and what is malicious.

The article also highlights a more subtle defensive problem: delays. The authors of the worm included time gaps so that some capabilities might not run for hours or even days after the initial foothold. That kind of staging makes it harder for defenders to connect a suspicious event with a later, more damaging outcome.

For teams building with AI, the takeaway is that the trust layer matters as much as the model layer. If attackers can compromise credentials, package-management access, or development workflows, they may gain leverage over the systems used to build and ship software, not just over a single application.

What to watch

CrowdStrike says it has been working on ways to connect more of the dots, but Meyers stressed that broader collaboration will be needed as AI software development expands. The challenge, as WIRED frames it, is that the attack surface is evolving alongside the tools organizations rely on to build code.

That means security teams will likely need to pay closer attention to the behavior of AI development pipelines, not just the endpoints and applications that result from them. Areas to watch include access-token handling, package-management credentials, unusual automation patterns, and delayed actions that may be part of a staged compromise.

The broader trend also matters. CrowdStrike says the activity fits into tactics associated with groups it tracks, including TeamPCP, which it calls “Altered Spider,” and North Korean groups targeting the AI software supply chain. Even without attribution for this specific worm, the report suggests that the AI toolchain itself is becoming an attractive place for attackers to hide.

As AI coding agents become more embedded in development workflows, the distinction between legitimate automation and malicious activity may continue to get harder to see. That makes the AI software stack an increasingly important security boundary to defend.

Watch next

How One Presentation Frames Surveillance Capitalism as a Design Problem — and a Civic One

How One Presentation Frames Surveillance Capitalism as a Design Problem — and a Civic One

A community talk argues that data-hungry platforms do more than track people: they shape behavior, concentrate power, and make privacy harder to defend without public pressure.

ClickFix Is No Longer Just a Low-End Scam — Even Elite Hackers Are Using It

ClickFix Is No Longer Just a Low-End Scam — Even Elite Hackers Are Using It

A social-engineering trick once associated with lower-end crime is being adopted by more sophisticated threat actors, broadening its importance for defenders.

What Trump’s newly declassified election documents do — and don’t — show about US voting risks

What Trump’s newly declassified election documents do — and don’t — show about US voting risks

Trump is using a fresh trove of declassified material to argue that American elections remain vulnerable, but the documents described in the source context mostly revisit long-known concerns rather than proving past election outcomes were altered.

Sources

Analytics, advertising, and privacy choices

We use analytics and advertising cookies only with your permission. You can change this choice later from the footer.

Privacy policy