Back Redpacketsecurity AI Coding Tools Are Now Prime Targets for Threat Actors, Google Warns
AI coding tools are becoming a major target for cybercriminals, with Google warning that rapid adoption is increasing software supply chain and data security risks.
AI Coding Tools Are Now Prime Targets for Threat Actors, Google Warns
The rapid adoption of AI-assisted coding tools has made them a primary target for threat actors, according to a new report from the Google Threat Intelligence Group (GTIG).
Researchers said the changing approach to software development contributed to several large-scale software supply chain compromises during 2025 and early 2026.
Several factors have increased operational risks across the software ecosystem. The rapid integration of large language models (LLMs) into production environments has driven growth in open-source resources designed to support AI use cases, including model context protocol (MCP) servers.
GTIG also reported that AI assistants have accelerated software development. As a result, developers may be giving less scrutiny to third-party packages and dependencies.
The researchers highlighted the activity of UNC6780, a financially motivated threat actor linked to a series of large-scale open-source software supply chain compromises. The group has targeted ecosystems including PyPI, npm and Docker Hub.
UNC6780 primarily targets AI environments and software dependencies for initial access. Its Dustmaker credential stealer uses several techniques, including extracting tokens from the process memory of GitHub Actions runners. Those tokens can then allow the group to publish compromised package versions that pass valid automated trust checks used by AI coding systems.
In another approach, Dustmaker drops or modifies malicious files in hidden project workspace directories used by AI coding assistants. This enables the malware to blend into ordinary developer activity and reduce the likelihood of detection.
After gaining initial access, UNC6780 has also been observed collecting credentials for AI tools and selling them to other cybercriminal groups.
“The publicity, apparent success, and open-source release of UNC6780 malware will likely spur adversary emulation of these tactics,” GTIG wrote in its report , dated September 8.
Attackers Are Targeting Proprietary AI Data
During the second quarter of 2026, a range of threat actors increasingly targeted proprietary AI research and models. Those groups included state- espionage actors and data extortion gangs.
The activity extended beyond AI laboratories and frontier AI companies . Organizations using AI in critical sectors, including government, military and healthcare, were also targeted.
GTIG observed one cyber-espionage campaign conducted by a Chinese nation-state actor tracked as UNC6508. The group specifically targeted proprietary AI research at academic, medical and military research institutions in North America.
Researchers also observed multiple data theft and extortion operations during Q2. In these incidents, attackers stole proprietary AI data such as models, skills, prompts, source code and related research. They then threatened to publish the information unless the affected companies paid a ransom.
The targeted organizations operated in the technology, healthcare, pharmaceutical, and media and entertainment sectors across North America and Europe.
Threat Actors Continue Experimenting With AI
GTIG identified another significant trend during Q2: threat actors are expanding their use of AI throughout attack lifecycles. Their activity is moving beyond using AI to support malware and tool development. Notable examples included:
A Chinese-nexus actor attempted to use Gemini to create an automated penetration-testing framework. The group aimed to develop an agentic architecture that could observe a target’s state, reason through possible actions and execute tasks in unpredictable environments.
A financially motivated threat actor used an AI coding chatbot and a set of agent instructions to build an autonomous, multi-agent attack framework. After compromising an organization’s cloud infrastructure, the group used the framework to plan, build and execute a mass credential-harvesting campaign in less than six hours.
A command-and-control (C2) server hosted an automated reconnaissance and credential-management framework called “Recon,” which was designed for offensive agentic harvesting. Shortly after GTIG identified the server, its exposed directory became a live production frontend dashboard for organizing, validating and managing more than 23,800 harvested secrets in real time, including API keys for cloud and AI services.
John Hultquist, chief analyst at GTIG, said the findings suggest that every threat actor is now using AI in some capacity and benefiting from the technology.
“At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited. Like everyone else, we’re concerned the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary,” Hultquist warned.
He added: “Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to.”
Read now: Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
