A dangerous new malware campaign has emerged in the software world, targeting developers, CI pipelines, and AI coding platforms. This attack uses a large-scale supply chain worm that spreads through malicious npm packages. Researchers have identified it as a serious threat, calling it SANDWORM_MODE, named after environment variables embedded in its code. The malware is










