thehackernews.com 8 Sept 2026, 13:48 UTC

TeamPCP Uses Autonomous AI Agents to Scale Credential Theft Attacks

CyberSIXT Evidence Panel
Threat Actor

GOOGLE Threat Intelligence Group (GTIG) reports that cybercriminals are increasingly using autonomous AI agents to run credential-harvesting campaigns at scale. In a six-hour operation observed by GTIG, attackers used an autonomous, multi-agent framework to scan, harvest credentials from third-party services, and co‑opt victim cloud environments to support unauthorized AI workloads.

The campaign leveraged a preconfigured playbook built with AI coding chatbots, enabling automated discovery, scanning, and extraction without human input.

The operation is attributed to TeamPCP (also known as Altered Spider and UNC6780), which has a history of large-scale software supply chain compromises on PyPI, npm, and Docker Hub. Two credential stealers were deployed: SANDCLOCK (an earlier component) and DUSTMAKER (the later, cross‑platform JavaScript payload).

SANDCLOCK targeted Linux environments and Kubernetes and included container-escape functionality and wallet-focused capabilities; DUSTMAKER focused on credential theft for extortion and carried AI-targeting techniques such as workspace poisoning and prompt injection to evade defence. GTIG notes these tools are being used to compromise AI coding assistants and related cloud/developer assets, with monetisation via direct sale or extortion-linked groups.

Evidence cited includes observed AI-assisted workflow for vulnerability discovery, IP rotation, and autonomous pipeline management. In response, Google discusses mitigations through modelling safety frameworks (Frontier Safety Framework and Critical Capability Levels) and tension between open-weight models and enterprise containment needs, underscoring the need for industry-wide safety baselines and platform policies to curb abusive AI use.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline