When a Worm Can't Rob You, It Burns the House Down

September 21, 2026 · SPR{K}3 Research

The new class of threats we built Defend to stop

In late 2025, a piece of malware made a decision that should bother anyone who runs code for a living. The second wave of the Shai-Hulud worm — the first self-replicating worm the npm ecosystem had ever seen — shipped with a fallback. If it couldn't steal your credentials, couldn't reach GitHub, couldn't find a token to exfiltrate, it didn't quietly move on. It tried to securely erase every writable file in your home directory.

Rob you if it can. Destroy you if it can't.

That is the shape of the modern threat, and it is the shape we built Defend to stop.

The attack is a sequence, not a signature

Shai-Hulud wasn't one malicious file you could blocklist. It was a sequence: a package gets installed, a script reads credentials from the machine, those secrets leave over the network, and the worm republishes itself into the next victim's supply chain. Every single step, taken alone, looks like something a developer's machine does a hundred times a day. Install a package. Read a config file. Make a network call. Push to a repo.

The malice isn't in any one event. It's in the order.

This is what the last two years of supply-chain and AI-infrastructure attacks have in common, and it's why a generation of security tools keep missing them. Signature scanners look for known-bad files. Allowlists look for known-bad commands. Both ask the same narrow question — "is this one thing dangerous?" — when the dangerous thing is the path traced across a dozen ordinary-looking events.

Where these threats actually live

The machines being targeted now are not the laptops in a sales department. They are the boxes that build and run software: developer workstations, CI runners, training nodes, inference servers, and the new and rapidly growing category of machines that run AI agents. These hosts have something attackers want — credentials, model weights, pipeline access — and they run toolchains that traditional endpoint security has never understood.

The threat classes we see concentrating there:

How Defend handles them

Defend watches behavior, not files. It models the chains — download then execute, read credentials then call out to the network, a web server that suddenly spawns a shell — and it raises an alert when a sequence of individually-innocent events adds up to something that has no benign explanation. The chain is the signal.

Two design choices make that practical to run on a real working machine.

It only stops annihilation. Defend does not get in your way. It runs with no inline proxy, no interception, no latency. The only things it actively kills are the irreversible ones — filesystem wipes, fork bombs, and credential or data exfiltration. Everything else is logged, scored, and surfaced for you to decide. Note what that list includes: the exact destructive home-directory wipe that Shai-Hulud 2.0 falls back to. That's not a coincidence. The annihilation set is built from the things you can never take back.

It's precise about what it spares. A security tool that cries wolf gets turned off, and a tool that kills the wrong process is worse than no tool at all. So Defend distinguishes a legitimately notarized application doing a download-then-execute — a container runtime pulling an image, an installer doing its job — from malware performing the identical sequence. Trusted, signed software on the handful of false-positive-prone chains is spared; the dangerous chains, the ones with no good explanation, are never spared for anyone. The verification fails closed and is resilient to transient hiccups, so a real tool doesn't get killed for a slow signature check, and unverified code never slips through.

Offense is what keeps the defense honest

The detection patterns inside Defend aren't bought from a threat feed. They come from our own vulnerability research — the same work behind 14 confirmed CVEs across NVIDIA's security bulletins and confirmed findings at Meta, Microsoft, Google, Amazon, and Intel. Every vulnerability we confirm becomes a detection pattern, and that registry refreshes daily.

It also moves. Over any given week the coverage shifts toward wherever the threats are actually heading — lately, supply-chain compromise and data exfiltration, exactly the directions Shai-Hulud and its successors have pushed the whole ecosystem. Defense that's downstream of live offense doesn't go stale, because the people writing the detections are the same people finding the bugs.

The takeaway

The attackers have already moved. They've gone from single malicious files to multi-step chains, from pure theft to theft-or-destruction, from the office laptop to the machines that build and run your software and your models. The defense has to move with them — watch the sequence, stop only what's truly irreversible, spare what's legitimate, and learn from the offensive edge every single day.

That's what Defend is. If you run code, build models, or operate AI infrastructure on macOS, Linux, or Windows, it's built for the machine you actually work on.


SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.