www.infosecurity-magazine.com 8 Sept 2026, 12:02 UTC

Google Warns AI Coding Tools Fuel Software Supply Chain Attacks

CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
UNC6780

GOOGLE Threat Intelligence Group (GTIG) warns that AI-assisted coding tools have become a prime target for threat actors, contributing to several large-scale software supply chain compromises in 2025 and early 2026. The rise of large language models in production has boosted the quantity of open-source resources and reduced scrutiny of third‑party packages and dependencies, GTIG notes.

The financially motivated group UNC6780 has conducted extensive supply chain compromises across PyPI, npm and Docker Hub, using Dustmaker credential stealer malware to exfiltrate tokens from GitHub Actions runners and publish compromised packages that pass automated trust checks. Dustmaker also hides malicious files in AI coding assistant project workspaces to blend into developer environments.

After initial access, UNC6780 has shown a pattern of collecting credentials to AI tools and selling them to other criminal groups. GTIG cautions that the malware’s publicised success and open-source release are likely to spur emulation by other attackers.

GTIG’s Q2 2026 observations show threat actors expanding AI use beyond malware support to targeting proprietary AI data and models, with activity reaching government, military and healthcare sectors in North America and Europe.

Notable incidents include a cyber-espionage campaign by a Chinese nation-state actor (UNC6508) focusing on proprietary AI research across academic, medical and military institutions in North America, and multiple data theft extortion operations threatening to release stolen AI data unless ransom is paid.

In addition, actors experimented with AI during attack lifecycles, including attempts to build automated pentesting frameworks and autonomous, multi‑agent attack campaigns capable of rapid credential harvesting and real-time management of harvested secrets. John Hultquist of GTIG warns that all threat actors are employing AI to some degree, and that agentic, faster attacks will be difficult to counter.

View full article

Article by CyberSIXT