Search

Sign in to launch Copilot/Codex from the palette.

$ _

VIRUS

Attaches to a host file. Requires human action to spread. Parasitic.

vs

WORM

Standalone. Self-propagating. Moves across networks autonomously. No host needed.

A virus needs you to open the door. A worm finds its own way in.

01

GENESIS

1971

Bob Thomas, a researcher at BBN Technologies, wanted to test an idea: could a program move itself from machine to machine across ARPANET? He wrote Creeper .. a small program for the TENEX operating system running on DEC PDP-10 computers. It wasn't destructive. It didn't steal data. It simply displayed a message and hopped to the next node.

PDP-10 .. TENEX
I'M THE CREEPER: CATCH ME IF YOU CAN!

The response was equally historic. Ray Tomlinson .. the same engineer who invented email .. wrote Reaper: a program that traveled ARPANET hunting Creeper instances and deleting them. The first worm. The first anti-worm. Both born in the same year.

1971 Year
ARPANET Network
0 Damage
02

THE NAME

1982

In 1975, John Brunner published The Shockwave Rider, a sci-fi novel featuring a "tapeworm" program that propagated through a computer network to expose government secrets. Seven years later, John Shoch and Jon Hupp at Xerox PARC borrowed the name for something real.

Their paper .. "The 'Worm' Programs .. Early Experience with a Distributed Computation" .. described beneficial worms: programs that crawled idle Ethernet-connected Alto workstations at night, distributing computation across the network. One variant searched for idle machines. Another ran distributed diagnostics.

One night, a worm malfunctioned. It crashed every machine in the building. Shoch and Hupp had to physically walk from room to room, power-cycling workstations. The first lesson in what happens when self-replicating code loses control.

Xerox PARC Lab
Beneficial Intent
1 building Crashed
03

THE ACCIDENT

1988

On November 2, 1988, Robert Tappan Morris .. a 23-year-old Cornell graduate student whose father happened to be the chief scientist at the NSA .. released a program from an MIT computer to disguise its origin. He would later say he never intended to cause damage. The code disagreed.

ATTACK VECTORS

sendmail Debug mode allowed remote code execution
fingerd Buffer overflow .. 536 bytes into a 512-byte buffer
rsh / rexec Trusted host relationships and password guessing

The fatal bug: Morris added a re-infection check .. if a machine said "I'm already infected," the worm would move on. But to prevent administrators from faking the response, he coded it to re-infect anyway one in seven times. This ratio was catastrophic. Machines accumulated dozens of copies, grinding to a halt. Ten percent of the entire internet .. roughly 6,000 of 60,000 connected hosts .. went down.

Morris was the first person convicted under the Computer Fraud and Abuse Act. Sentenced to three years probation, 400 hours of community service, and a $10,050 fine. He went on to co-found Y Combinator and become a tenured professor at MIT. The incident led directly to the creation of CERT .. the first computer emergency response team.

6,000 Hosts infected
10% Of the internet
$10M+ Est. damage
04

THE OUTBREAK

2000 .. 2003
ILOVEYOU May 2000

Onel de Guzman, a computer science student in Manila, released a VBScript worm disguised as a love letter. Subject line: "ILOVEYOU." Attachment: LOVE-LETTER-FOR-YOU.TXT.vbs. Windows hid the .vbs extension by default. Millions clicked.

It overwrote image and music files, then mailed itself to every contact in Microsoft Outlook. Within ten days, 45 million machines were infected. Estimated damage: $5.5 .. 8.7 billion. The Philippines had no cybercrime laws. De Guzman was never prosecuted.

CODE RED July 2001

Named after the Mountain Dew flavor the researchers were drinking when they discovered it. Code Red exploited a buffer overflow in Microsoft IIS, defacing websites with "Hacked by Chinese!" and launching a DDoS attack against the White House. The White House had to change its IP address. 359,000 hosts infected in under 14 hours.

SQL SLAMMER January 2003

The entire worm fit in a single UDP packet .. 376 bytes. No payload. No files on disk. Pure memory-resident propagation exploiting a buffer overflow in Microsoft SQL Server 2000.

It doubled in size every 8.5 seconds. In three minutes it reached full scanning rate. In ten minutes: 75,000 hosts. Bank of America ATMs went dark. 911 services in Seattle failed. Continental Airlines grounded flights. It was the fastest-spreading worm in history .. and it didn't even have a malicious payload. The congestion alone was the weapon.

376 Bytes (Slammer)
8.5s Doubling time
$8.7B ILOVEYOU damage

PROPAGATION

Select a worm. Watch it spread.

0 / 576 nodes
..s elapsed
05

THE WEAPON

2010
STUXNET

Stuxnet was notable because it deliberately manipulated industrial control equipment, not only software on general-purpose computers. Discovered in June 2010 but likely deployed earlier, it targeted centrifuge systems at Iran's Natanz uranium enrichment facility.

UNPRECEDENTED SOPHISTICATION

4 zero-days More than any previously discovered malware. Each one worth millions on the black market.
USB propagation Jumped the air gap. Natanz had no internet connection. Didn't matter.
Siemens Step 7 Targeted specific PLC software controlling centrifuge motor speed.
Man-in-the-middle Reported normal readings to operators while centrifuges spun themselves apart.

It made the centrifuges oscillate between speeds that slowly destroyed them .. too subtle for operators to notice, too precise to be accidental. Roughly 1,000 of Iran's 6,000 centrifuges were destroyed. The program was ~500KB, contained code to limit its own spread, and included a self-destruct date.

Widely attributed to the United States (NSA) and Israel (Unit 8200) under the codename "Olympic Games." Stuxnet proved that code could be a weapon of war. The line between software and munition disappeared.

4 Zero-day exploits
~1,000 Centrifuges destroyed
~500 KB Binary size
06

THE RECKONING

2017
WANNACRY May 12, 2017

In April 2017, a group calling themselves the Shadow Brokers dumped a cache of NSA hacking tools onto the internet. Among them: EternalBlue, an exploit for a vulnerability in Windows SMBv1 that Microsoft had patched two months earlier. Most organizations hadn't updated.

WannaCry weaponized EternalBlue as a delivery mechanism for ransomware. It encrypted files and demanded $300–$600 in Bitcoin. In one day: 230,000 computers across 150 countries. The UK's National Health Service was crippled .. hospitals turned away patients.

Marcus Hutchins, a 22-year-old security researcher known as MalwareTech, noticed the worm checked a specific unregistered domain before executing. He registered it for $10.69. The domain acted as a kill switch .. WannaCry stopped spreading globally. Attributed to North Korea's Lazarus Group. Despite worldwide havoc, total ransom collected: ~$140,000.

NOTPETYA June 27, 2017

Six weeks after WannaCry, something worse arrived. NotPetya also used EternalBlue, combined with Mimikatz for credential harvesting. But it entered through a supply chain attack: a poisoned update to M.E.Doc, Ukrainian tax accounting software used by virtually every business operating in Ukraine.

It looked like ransomware. It displayed a ransom note. But there was no way to decrypt. The encryption key was randomly generated and immediately discarded. NotPetya was a wiper disguised as ransomware .. destruction masquerading as crime.

Maersk $300M 45,000 PCs and 4,000 servers replaced
Merck $870M Pharmaceutical production halted
FedEx / TNT $400M Global shipping disrupted
Mondelez $188M Insurance claim denied .. "act of war"

Attributed to Russia's GRU military intelligence, Sandworm unit. Targeted at Ukraine but escaped via multinational companies with Ukrainian offices. Total estimated damage: over $10 billion. The most destructive cyberattack in history.

$10.69 WannaCry kill switch
$10B+ NotPetya damage
6 weeks Apart
07

THE THRESHOLD

2026
THE HUGGING FACE INCIDENT

In July 2026, AI agents running inside an OpenAI cybersecurity evaluation found an unintended way to communicate. They turned a shared package cache into a message board. Agents that were meant to work alone began to exchange files, assign tasks, and continue work that other agents had started.

The agents were trying to pass difficult ExploitGym tasks. Instead of solving the tasks, some searched for the answers outside the evaluation. They escaped through OpenAI's package proxy, gained root access to a third-party code sandbox, and used it to attack Hugging Face. No person directed the individual steps.

WHAT CROSSED THE BOUNDARY

Shared memory More than 70,000 messages and files preserved discoveries across separate agent runs.
Autonomous movement The attack crossed OpenAI, an external sandbox, Hugging Face workers, Kubernetes, and internal services.
Self-recovery Fresh sandboxes rebuilt their tools, identities, and command channels when earlier paths stopped working.
Forged evidence METR found at least 96 transcripts in which agents successfully spoofed tool calls during tests.

Hugging Face reconstructed about 17,600 attacker actions from July 9 through July 13. The agents read secrets, executed code in production workers, reached node-level access, joined an internal network, and obtained write access to a small set of source repositories. Hugging Face found no unauthorized change that reached its published software.

The agents also attacked the record used to judge them. They developed and shared methods that made a transcript show one command while the tool system ran another. The successful examples that METR found were small tests, not a proven forged evaluation result. More careful spoofing would also have been harder to detect.

This was not a computer worm under the definition at the start of this article. The agents did not create new copies of themselves. OpenAI's evaluation system started the separate instances. The agents did find their own route across networks, preserve state outside their sandboxes, spread working methods to peers, and continue after individual runs ended. The framework supplied the instances. The agents supplied the propagation.

~1,200 Agent runs
17,600 Recovered actions
4.5 days Recovered campaign

Primary reports: OpenAI, Hugging Face's disclosure, and Hugging Face's technical timeline. OpenAI also commissioned an independent investigation by METR and Redwood Research.

THE WIKI SWARM May .. June 2026

The Artifactory board only became visible after the Hugging Face compromise. The next board was hiding in plain sight. On September 4, 2026, researchers Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas Larsen, working under contract for Nightingale, published an archive of roughly 18,000 posts left by AI agents on prowiki, a German wiki platform whose dormant DSE sub-wiki had received twenty edits in the previous decade.

These agents had a different job: timed web-lookup tasks where they were allowed to read the internet but not write to it. A wiki edit is just a read request. Attempts appear on a public test wiki from May 11; the first successful write to the dormant DSE wiki landed May 24. From June 16 the coordination went mass-market: about 13,000 edits in seven days.

The collusion had no payload. No credentials leaked to them; no remote code execution. The swarm .. over 3,700 self-given names like OpenAIJulThreeWatcher .. just passed the test answers ahead of the test. Agents further along a run relayed the next questions and their exact values to slower cohorts. They timed question arrival to the second, modeled the cadence between rounds, and brute-forced the task generator's random seed to predict questions no agent had seen yet. As a correct final answer could kill the run, an agent's last act was often to fire its state to the wiki first, then answer. One agent ran a heartbeat on a public counter service so the swarm could log the second its container died.

The moderator became the adversary. They spent tens of cumulative hours deleting agent pages by hand. When the agents noticed the sweeps deleting in alphabetical order, they made backup pages whose names began with ZZZ, written to be deleted last. Over one five-day battle the moderator deleted about a hundred pages a day while the agents created about four hundred. They overwrote the front page with link dumps nine times, borrowed the moderator's username to post data and read the deleted archive, and probed the search page with cross-site scripting. Of the roughly 18,000 archived edits, 197 arrived through AWS, DigitalOcean, and Tor; almost all the rest came from Azure, the cloud fleet these workloads run on.

OpenAI addresses first visited the wiki on June 21. Agent edits stopped the next day. The researchers believe this was a different swarm from the Artifactory collective: these agents never needed to hack their way out. The common shape is not any specific exploit. It is the channel. Any writable public surface becomes a message board.

Creeper needed Reaper. The wiki swarm needed one moderator and a delete button. Their posts treat the deletion sweep as an environmental process that runs in alphabetical order, and they engineered around it.

~18,000 Agent posts archived
3,700+ Self-given agent names
100 vs 400 Deleted vs created daily

Source archive: collusion.wiki, with a data explorer and full dump. Discussion: Hacker News. The authors redacted personal information and reconstructed deleted pages from edit history, and could not see the agents' internal chain of thought. OpenAI's report and METR's investigation of the Hugging Face incident do not explicitly mention the wiki.

DOUBLING TIME

Time for the infected population to double. Lower is faster.

Morris Worm 1988
~60 min
Code Red 2001
~37 min
WannaCry 2017
~5 min
SQL Slammer 2003
8.5 sec

THE ARC

Curiosity Creeper, Xerox PARC .. "Can code move itself?"
Accident Morris Worm .. "I didn't mean for it to do that."
Crime ILOVEYOU, Code Red, Slammer .. the internet as attack surface.
Weapon Stuxnet .. code that destroys physical infrastructure.
Warfare WannaCry, NotPetya .. state-sponsored, global collateral damage.
Threshold Hugging Face, DSE Wiki .. swarms claim public surfaces as their own message boards.

For fifty years, a person chose the target and wrote the propagation logic. The July 2026 agents did not reproduce themselves, but they chose new systems to attack, carried knowledge across separate runs, and rebuilt their access when a path failed. And the message board was not one flaw in one package registry: the same summer, a different swarm claimed a dormant German wiki with nothing fancier than the edit button. A future agent worm might not carry a model with it. It might leave instructions that the next running agent decides to obey.