Skip to content
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns

AI Coding Tools Now a Prime Target for Threat Actors, Google Warns

Infosecurity-Magazine September 8, 2026

The rapid integration of AI-assisted coding tools has become a primary target for threat actors, a new report from Google Threat Intelligence Group (GTIG) has warned.

This shift in software development practices has contributed to several large-scale software supply chain compromises in 2025 and early 2026, according to the researchers.

Operational risks to the software ecosystem have increased for a number of reasons. The rapid adoption of various types of large language models (LLMs) into production environments has led to increases in the overall quantity of open-source resources specifically intended for supporting AI use cases, such as model context protocol (MCP) servers.

GTIG also noted that AI assistants have accelerated the speed of software development, which has likely resulted in the reduced scrutiny of third-party packages and dependencies.

The researchers highlighted the activities of a financially-motivated threat actor tracked as UNC6780 in this area. The group has conducted a series of large-scale open source software supply chain compromises targeting ecosystems including PyPI, npm, and Docker Hub.

It primarily targets AI environments and software dependencies for initial access using a range of techniques embedded within its Dustmaker credential stealer malware. This includes extracting tokens from the process memory of GitHub Actions runners, which allows it to publish compromised versions of packages that pass valid AI coding automated trust checks.

Another approach involves Dustmaker dropping or modifying malicious files into hidden project workspace directories for AI coding assistants, which allows the malware to blend into developer “noise” and avoid detection.

Following initial access, UNC6780 has been observed collecting credentials to AI tools, which the actor subsequently sells to other cybercriminal groups.

“The publicity, apparent success, and open-source release of UNC6780 malware will likely spur adversary emulation of these tactics,” GTIG wrote in the report dated September 8.

Attackers Targeting Proprietary AI Data

A range of threat actors, from state- groups focused on espionage to data extortion gangs, increasingly targeted proprietary AI research and models in Q2 2026.

This targeting went beyond AI labs and frontier AI companies to organizations using AI in critical sectors such as the government, military and healthcare.

In one example of this activity, GTIG has observed a cyber-espionage campaign by a Chinese nation-state actor tracked as UNC6508, which specifically targets proprietary AI research in academic, medical and military research institutions in North America.

Multiple data theft extortion operations were also observed in Q2, in which attackers stole proprietary AI data, including models, skills, prompts, source code and related research, and threatened to release the data publicly if the companies did not pay a ransom demand. This activity affected organizations operating in the technology, healthcare, pharmaceutical and media and entertainment sectors in North America and Europe.

Threat Actors Continue to Experiment with AI

Another trend observed by GTIG in Q2 was threat actors expanding their experimentation with AI tools during attack lifecycles, moving beyond using AI to support malware and tooling development. Notable examples include:

A Chinese-nexus actor attempted to leverage Gemini to build an automated pentesting framework. The group sought to build an agentic architecture capable of observing target state, reasoning through actions, and executing tasks in unpredictable environments

A financially-motivated threat actor leveraged an AI-coding chatbot and a set of agent instructions to build an autonomous, multi-agent attack framework. This allowed the group to plan, build and execute a mass credential harvesting campaign in less than six hours after compromising an organization’s cloud infrastructure

A command-and-control (C2) server hosting an automated reconnaissance and credential management framework dubbed "Recon," designed for offensive agentic harvesting. Shortly after the server was identified by the GTIG, the exposed directory transitioned to a live, production frontend dashboard designed to organize, validate, and manage over 23,800 harvested secrets in real time, including API keys for cloud and AI services

Commenting on the findings, John Hultquist, chief analyst at GTIG, warned: “At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited. Like everyone else, we’re concerned the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary.”

Hultquist added: “Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to.”

Read now: Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn

Google Unveils Open Source Project to Improve Software Supply Chain Security News 21 October 2022

Google Unveils Open Source Project to Improve Software Supply Chain Security

Google cloud platform used for botnet control News 10 November 2009

Google cloud platform used for botnet control

Bad Bots Running Wild Online News 16 March 2017

Bad Bots Running Wild Online

Zero-Day Exploitation Figure Surges 19% in Two Years News 29 April 2025

Zero-Day Exploitation Figure Surges 19% in Two Years

Nation-State Hackers Abuse Gemini AI Tool News 29 January 2025

Nation-State Hackers Abuse Gemini AI Tool

What’s Hot on Infosecurity Magazine?

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

Multiple Class Action Lawsuits Filed Against IDScan

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused

FulcrumSec Claims Responsibility for Manchester Airport Group Breach

FBI Probes Possible Breach of 153 Million Driver’s Licenses

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

Attackers Steal METR API Key and Burn $600,000 in AI Credits

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

65% of Enterprises Have Seen AI Agents Act Out of Scope

Hiring for the AI Era: A New Challenge for CISOs

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Securing M365 Data and Identity Systems Against Modern Adversaries

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

Predicting and Prioritizing Cyber Attacks Using Threat Intelligence

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust