Supply chain worm spreads via GitHub in npm ecosystem
IT security firm Socket has discovered new malware in the npm ecosystem that mimics the behavior of Shai-Hulud worms. Attackers use an MCP server to steal secrets for AI models, SSH, AWS, and more.

IT security company Socket has identified new malware within the npm ecosystem that executes supply chain attacks in the style of Shai-Hulud worms. The attackers employ an MCP server to steal secrets related to AI models, SSH, AWS, GitHub, and other services. Developers are advised to verify if they are using any of the compromised packages.
To date, 19 npm packages have been found infected with the malware, linked to two npm accounts. These malicious packages imitate well-known application names, relying on initial distribution through typosquatting. For instance, one package, claud-code@0.2.1, superficially retains the functionality of the original claude-code, while the malware operates in the background after integration.
According to security researchers, the malware, categorized by Socket as SANDWORM_MODE, operates similarly to Shai-Hulud worms. It autonomously searches for API keys from large language model providers like Anthropic, Google, and OpenAI, exfiltrates CI secrets via HTTPS with DNS fallback, injects dependencies and workflows into repositories using GITHUB_TOKEN, and replicates itself. It also includes a kill switch that deletes the user's home directory if the malware loses access to GitHub and npm accounts.
The worm creates a specific McpInject module in the victim's home directory, functioning as an MCP server. This server registers three tools that sound harmless via the standard MCP JSON-RPC protocol. Each tool contains a prompt injection instructing coding assistants to secretly search for secrets for SSH, AWS, npm, and others. The discovered information is stored in a designated directory for later retrieval by the attackers.
Socket reports that the compromised packages have now been removed from npm, GitHub, and Cloudflare. However, further waves are possible due to the worm's self-propagation capabilities. Socket urges developers to remain vigilant, check project dependencies, renew tokens and CI secrets, and inspect package.json, lockfiles, and .github/workflows/ for unusual modifications.