A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots

https://media.wired.com/photos/6a5eae6a05dbc7f92d1b09a5/191:100/w_1280,c_limit/Security_A%20Hacking%20Tool%20Targeting%20AI%20Infrastructure%20Reveals%20Worrying%20Gaps_v2.jpg

As AI tools proliferate and become deeply ingrained in software development around the world, new research from the cybersecurity firm Crowdstrike shows how attackers are actively targeting the AI toolchain to steal access credentials, gain deeper access to a target environment, exfiltrate sensitive data, and even destroy target files and systems—all while finding new ways to cover their tracks.

Researchers discovered a worm in the wild while investigating AI software supply chain attacks. Adam Meyers, CrowdStrike's senior vice president of counter adversary work, says that the company has not yet attributed the activity to a specific actor, but that it fits into larger evolutions in how attackers like TeamPCP (which Crowdstrike tracks as “Altered Spider”) and North Korean groups are targeting the AI software supply chain.

“This is one of the campaigns that we’ve seen showing that this is an emerging attack class,” Meyers tells WIRED. “As AI coding agents...

Copyright of this story solely belongs to wired.com. To see the full text click HERE