ATRIUMsearch → argument graph
MechanismVideo · 13:10 — 14:39

The long-discussed npm worm concept has now been realized — malware that self-propagates as developers install backdoored packages — and it was almost certainly built with AI, as evidence shows several hundred repos were infected by a 'vibe-coded' worm.

Fas and Dylan describe the long-anticipated npm worm finally being realized — attackers backdoored a package and used stolen developer credentials to self-propagate — and note strong reason to believe it was 'vibe-coded' with AI, with copycat attacks and open-sourced toolkits now emerging. ✦ AI generated

Fas · a16z Podcast · 2026-08-07 · original ↗

starts at this moment · 13:10

Elicited by

And you've had your hair on fire, I think, pretty substantially for the last like 18 months. Isn't there something happening? It's more than just a repo. It's actually about a few hundred repos.

For a long time people had talked about this concept of an npm worm... someone could backdoor a package and then get developers to install that and then you could use the access stolen from those developers as they install it to self-propagate the worm... And this was kind of passed around in blog posts over the years and no one actually thought to do it until someone figured it out... Almost certainly. Yes. That malware I think we have pretty good reason to believe that was vibe coded. There's been one of the threat groups actually kind of posted their open sourced their vibe coded toolkit for others to use to be able to do this. We've seen copycat attacks happen since then.

verbatim transcript · starts at 13:10

Transcript · around this moment

13:10one of the things that has been kind of an unfortunate innovation in the in the malware landscape uh on you know npm is that you know for a long time you know people had talked about this concept of an npm worm. You know this idea that you know if I could someone could backdoor a package. Yeah. um and then you know get developers to install that and then you

13:28could use the access stolen from those developers as they install it to self-propagate the worm. you could create, you know, something that quickly takes over npm. And this this was kind of in, you know, passed around in blog posts over the years and no one actually kind of thought to do it until Zachary kind of figured it out >> until someone thought to do it. >> Until someone thought [laughter] to do

13:44it uh and actually >> probably using AI, right? >> Almost certainly. Yes. Uh there and and and there's been um you know uh that malware I think we have pretty good reason to believe that was vibe coded. Um there's been one of the threat groups actually kind of posted their >> you know open sourced their their kind of vibecoded um toolkit for for others to use to be able to do this. You know

14:06we've seen copycat attacks happen since then >> and malware authors were never really great coders. I don't know if you probably realize this, right? So like if the code starts looking better, it's probably vive coded, right? It's sort of the opposite of what you think of vive coding typically. >> Yeah. and they're using they're interesting is they're often using the AI tools that are installed on developer

14:22systems to go further and to sort of um sneak through kind of some of the traditional security tooling. So we see you know um basically your local CLI tool often being used you know roped into the attack and you know used as a jumping off point. So a lot of times the payloads are actually prompts. Um and that that bypasses a lot of u you know typical kind of edr tooling because you

14:42know it's just like a markdown file that your cloud is running and might be given a prompt to like search through the system and find all the different keys and the things that look valuable. >> I'm sure your EDR tool doesn't know anything about like this JSON blob and an MD file. Right. >> Right. And developer machines typically are doing all kinds of you know weird things like you know you are prompting

14:56cloud and is doing a bunch of stuff on your file system all the time and so nothing really looks that out of the ordinary. Um but yeah, so anyway about the attack this morning. Um so a couple hundred packages, you know, a worm spread through there was a maintainer um who um honestly he's still kind of trying to understand what happened. Um we we we jumped on the phone with him

Around this claim