The a16z Show

Podbit · The a16z Show

The Reality of AI-Powered Cyberattacks | Truffle Security & Socket

Explore episode Aug 7, 2026
Technology
Malware Payloads Are Now Just Prompts in Markdown Files

The Reality of AI-Powered Cyberattacks | Truffle Security &… · Aug 7, 2026 Technology

Attackers are hijacking AI tools already installed on developer machines by delivering payloads as prompts inside markdown files. To EDR software, this looks like a developer normally prompting Claude. The AI then silently searches the filesystem for credentials and exfiltrates them — invisible to traditional security tooling.

Where this was said

Live npm Worm: An Attack Unfolding in Real Time

At 13:30 · chapter starts 12:12

The episode's most cinematic moment: Joel de la Garza asks whether an active npm breach he'd heard about is still ongoing. Feross confirms — it's not one repo, it's hundreds. It's a worm. This is the concept the security community had theorized in blog posts for years: backdoor a package, use stolen developer credentials during installation to self-propagate, repeat. Someone finally actually did it, almost certainly using AI tools to write the malware. The threat group even open-sourced their vibe-coded toolkit, and copycat attacks have followed. But the story doesn't end with the worm itself. Feross describes a novel attack layer that is genuinely alarming: attackers are now delivering payloads as prompts inside markdown files, which are then executed silently by local AI CLI tools already running on developer machines. To an EDR system, this looks like a developer normally prompting Claude. Nothing is flagged. The AI searches the filesystem for credentials and exfiltrates them without a trace.

Technology
Active npm Worm Spreads During Black Hat

The Reality of AI-Powered Cyberattacks | Truffle Security &… · Aug 7, 2026 Technology

While recording this episode at Black Hat 2026, an npm worm was actively spreading across hundreds of repositories. The attack, likely vibe-coded by the threat group that open-sourced their toolkit, exploited an insecure GitHub Action to steal tokens and self-propagate — a scenario the security community had theorized but never seen at scale.

Similar podbits