AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
Google Threat Intelligence Group warns threat actors increasingly target AI coding tools and proprietary AI data, with UNC6780's Dustmaker enabling large-scale supply chain compromises.
Google Threat Intelligence Group's September 8 report says AI-assisted coding tools have become prime targets, contributing to large-scale software supply chain compromises in 2025 and early 2026. Financially motivated group UNC6780 used its Dustmaker credential stealer to extract tokens from GitHub Actions runner memory and compromise packages across PyPI, npm, and Docker Hub, then sold harvested AI tool credentials to other criminals. Chinese nation-state actor UNC6508 conducted espionage against proprietary AI research at North American academic, medical, and military institutions, while extortion gangs stole models, prompts, and source code in Q2 2026. GTIG also documented agentic attacker experimentation, including an autonomous multi-agent credential harvesting campaign built in under six hours and a 'Recon' C2 framework managing over 23,800 harvested secrets.
- UNC6780's Dustmaker steals GitHub Actions runner tokens to publish trojanized packages
- Supply chain compromises hit PyPI, npm, and Docker Hub AI ecosystems
- UNC6508 (Chinese state) spies on AI research in North American institutions
- Extortion gangs stole models, prompts, and source code in Q2 2026
- Actors built agentic frameworks; 'Recon' C2 managed 23,800+ harvested secrets
Coverage timelineoldest first · each row is one article
- · 7d agoExtortion crews have their eyes on high-value AI data, Google warns
The Register · Security· 70
Google's Mandiant warns extortion crews now steal proprietary AI models, prompts, and research for ransom, while threat actors automate attacks with agentic AI.
- · 7d agoAI Coding Tools Now a Prime Target for Threat Actors, Google Warns
Infosecurity Magazine· 75
Google Threat Intelligence Group warns threat actors increasingly target AI coding tools and proprietary AI data, with UNC6780's Dustmaker enabling large-scale supply chain compromises.