*Here comes the Sandworm, agency fans

for those who might like a citable news article about the SANDWORM_MODE exploit, including the information summarized in the AI-generated summary screen-shotted in the OP, there's https://thehackernews.com/2026/02/malicious-npm-packages-harvest-crypto.html among others.

@bruces @electricarchaeo

Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens

19 npm packages spread SANDWORM_MODE worm, stealing tokens, crypto keys, CI secrets, and AI API keys via MCP injection

The Hacker News