Sandworm_Mode works because it looks like normal AI-assisted development. The weak spot is not just secret theft. It is that build jobs, assistant-driven repo work, and automation now produce the same kinds of events the worm uses, so standard anomaly rules have little to separate malicious activity from day-to-day noise.
CrowdStrike says the worm spreads through malicious npm packages and trusted CI and AI-tooling workflows, and it steals npm, GitHub, cloud, cryptocurrency, and LLM-provider credentials. In its report, 9 of 14 observed behaviors produced any signal and only 2 reliably triggered alerts, which shows how much of this activity blends into ordinary development telemetry.
The risk is persistent access across packages, CI, cloud, and external AI services from one compromised workflow. Patching the original foothold does not fix secrets that were already exposed.