Breaking
SecurityDeveloping Story

Google Warns on AI Coding Tool Threats

Google Threat Intelligence Group warns AI coding tools are prime targets for supply chain attacks.

··2 hours ago·4 min read
a desk with several monitors
Photo by Boitumelo on Unsplash

Google's Threat Intelligence Group (GTIG) has issued a fresh warning that the rapid integration of AI-assisted coding tools has made them a primary target for threat actors. According to GTIG's analysis, this shift in software development practices contributed to several large-scale software supply chain compromises in 2025 and early 2026.

Why AI coding tools are now in the crosshairs

GTIG's report argues that the increased operational risks to the software ecosystem stem from the rapid adoption of various types of large language models (LLMs) into production environments. This has driven up the overall quantity of open-source resources intended to support AI use cases, such as model context protocol (MCP) servers.

AI assistants have also accelerated the pace of software development, which GTIG says has likely reduced scrutiny of third-party packages and dependencies. That combination—more AI-specific code and less careful review—creates fertile ground for attackers.

UNC6780: supply chain compromise at scale

The report highlights the activities of a financially-motivated threat actor tracked as UNC6780. The group has conducted a series of large-scale open source software supply chain compromises targeting ecosystems including PyPI, npm, and Docker Hub.

UNC6780 primarily targets AI environments and software dependencies for initial access using techniques embedded within its Dustmaker credential stealer malware. One method extracts tokens from the process memory of GitHub Actions runners, enabling the actor to publish compromised versions of packages that pass AI coding automated trust checks.

Another approach involves Dustmaker dropping or modifying malicious files into hidden project workspace directories for AI coding assistants, allowing the malware to blend into developer “noise” and avoid detection. Following initial access, UNC6780 collects credentials to AI tools, which it subsequently sells to other cybercriminal groups.

“The publicity, apparent success, and open-source release of UNC6780 malware will likely spur adversary emulation of these tactics,”

— GTIG, writing in its report dated September 8

Proprietary AI data becomes a prime target

Beyond supply chain attacks, GTIG observed that a range of threat actors—from state-sponsored espionage groups to data extortion gangs—increasingly targeted proprietary AI research and models in Q2 2026. This targeting extended beyond AI labs and frontier AI companies to organizations using AI in critical sectors such as government, military, and healthcare.

In one example, GTIG observed a cyber-espionage campaign by a Chinese nation-state actor tracked as UNC6508, which specifically targets proprietary AI research in academic, medical, and military research institutions in North America.

Data extortion and the AI theft wave

Multiple data theft extortion operations were also observed in Q2. In these cases, attackers stole proprietary AI data—including models, skills, prompts, source code, and related research—and threatened to release the data publicly if companies did not pay a ransom demand.

The affected organizations span the technology, healthcare, pharmaceutical, and media and entertainment sectors in North America and Europe. GTIG's findings suggest that AI-specific intellectual property is now being treated as a high-value extortion target.

Threat actors experiment with AI across attack lifecycles

GTIG also noted that threat actors are expanding their experimentation with AI tools during attack lifecycles, moving beyond using AI for malware and tooling development. Notable examples from Q2 2026 include:

  • A Chinese-nexus actor attempted to leverage Gemini to build an automated pentesting framework, aiming for an agentic architecture capable of observing target state, reasoning through actions, and executing tasks in unpredictable environments.
  • A financially-motivated threat actor used an AI-coding chatbot and a set of agent instructions to build an autonomous, multi-agent attack framework. This allowed the group to plan, build, and execute a mass credential harvesting campaign in less than six hours after compromising an organization's cloud infrastructure.
  • A command-and-control (C2) server hosted an automated reconnaissance and credential management framework dubbed “Recon,” designed for offensive agentic harvesting. Shortly after GTIG identified the server, the exposed directory transitioned to a live, production frontend dashboard designed to organize, validate, and manage over 23,800 harvested secrets in real time, including API keys for cloud and AI services.

Commentary from GTIG leadership

Commenting on the findings, John Hultquist, chief analyst at GTIG, warned: “At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited. Like everyone else, we’re concerned about the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary.”

Hultquist added: “Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to.”

Why this matters for organizations

These findings imply that AI is not merely a defensive tool but a force multiplier for attackers, enabling faster and more scalable operations. The rise of agentic AI, in particular, suggests that adversaries will increasingly automate the planning and execution of attacks, compressing timelines that security teams have relied on for response.

For organizations adopting AI-assisted coding, this may mean reassessing supply chain security and dependency review processes, given the reduced scrutiny that GTIG observed. For those holding proprietary AI data, the report implies that such assets are now a prime target for espionage and extortion, requiring focused protection.

#ai#supply chain#threat actors#google#unc6780#unc6508

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories