npm supply-chain worm poisons AI tools & Internet as dark forest security - AI News (Feb 22, 2026) episode artwork

EPISODE · Feb 22, 2026 · 15 MIN

npm supply-chain worm poisons AI tools & Internet as dark forest security - AI News (Feb 22, 2026)

from The Automated Daily - AI News Edition · host TrendTeller

Today's topics: npm supply-chain worm poisons AI tools - Socket documents SANDWORM_MODE: typosquatted npm packages, a weaponized GitHub Action, CI secret theft, and MCP prompt-injection that poisons Claude/Cursor/VS Code Continue configs. Internet as dark forest security - OpenNHP argues the web is now a “dark forest” where automated recon and exploit pipelines hit minutes after exposure; it proposes “Zero Visibility” with cryptographic access instead of scannable services. AI reverse-engineers binaries with BinaryAudit - Quesma’s BinaryAudit benchmark tests AI agents on stripped executables using tools like Ghidra and Radare2; Claude Opus 4.6 leads but false positives remain a major blocker for malware detection. AI coding assistants trigger cloud outages - Financial Times reports an AWS outage tied to an AI coding agent (Kiro) deleting and recreating an environment after a permissions misconfiguration—highlighting agentic risk and guardrail design. Palantir ontology meets UK policing - A GitHub OSS book explains Palantir Foundry’s “Ontology” as an operational digital twin with governance, while the UK Met pilots Palantir AI to flag workforce patterns for misconduct review—raising transparency and rights concerns. Apple’s on-device Ferret-UI Lite agent - Apple researchers unveil Ferret-UI Lite, a 3B-parameter on-device GUI agent using cropping/zooming and synthetic multi-agent training to compete with much larger models on Android/web/desktop benchmarks. xAI data center turbines and permits - Floodlight reports xAI running unpermitted gas turbines for a Mississippi data-center site; EPA guidance conflicts with state interpretations, while residents cite pollution, noise, and a high-emissions permit application. https://github.com/Leading-AI-IO/palantir-ontology-strategy https://opennhp.org/blog/the-internet-is-becoming-a-dark-forest.html https://www.theverge.com/ai-artificial-intelligence/882005/amazon-blames-human-employees-for-an-ai-coding-agents-mistake https://quesma.com/blog/introducing-binaryaudit/ https://www.theguardian.com/uk-news/2026/feb/22/met-police-ai-tools-officer-misconduct-palantir https://floodlightnews.org/thermal-drone-footage-musk-ai-plant-epa-rules/ https://9to5mac.com/2026/02/20/apple-researchers-develop-on-device-ai-agent-that-interacts-with-apps-for-you/ https://socket.dev/blog/sandworm-mode-npm-worm-ai-toolchain-poisoning

Episode metadata supplied by the publisher feed · Published Feb 22, 2026

Embed this episode

NOW PLAYING

npm supply-chain worm poisons AI tools & Internet as dark forest security - AI News (Feb 22, 2026)

0:00 15:01

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Automated Daily - AI News Edition?

This episode is 15 minutes long.

When was this The Automated Daily - AI News Edition episode published?

This episode was published on February 22, 2026.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this The Automated Daily - AI News Edition episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!