Google Names the Agentic Supply-Chain Actor

September 9, 2026 · SPR{K}3 Research

On September 8, Google's Threat Intelligence Group published a report that turned "threat actors using AI agents to compromise the software supply chain" from a forecast into a named actor, a named campaign, and a named clock: thousands of third-party credentials, harvested end-to-end, in under six hours.

The report is GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI, with same-day coverage from The Hacker News, SiliconANGLE, and Infosecurity Magazine. The Cloud Security Alliance research note on TeamPCP tracks the same actor through prior open-source-supply-chain campaigns.

The named actor

GTIG now tracks the group as UNC6780 — publicly known as TeamPCP, a financially motivated actor GTIG describes as "the most prolific active adversary targeting the software development supply chain" since early 2026. Two attributions matter:

The named malware

Two credential stealers appear by name in the tracker, one succeeding the other:

Those directories are the working state of an AI coding agent. A file that lands there is one the next agent session will read.

The named clock

The number that made the tier-1 headlines is this one: in Q2 2026, GTIG observed a threat actor compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential-harvesting campaign, thousands of credentials wide, in under six hours.

The classical incident-response window — hours to detect, triage, and contain — assumes an attacker taking days between steps. When reconnaissance, tool-building, and execution loops run inside an agent, the outer loop compresses into a single shift. Google's companion post says it directly: "human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond."

Why this one matters

Three claims land at named-vendor, named-actor, named-window resolution — and only one of them was public at this fidelity yesterday:

What actually catches this

The GTIG report describes a threat that already defeats pre-approval review — trojanized packages pass AI trust checks (Dustmaker), MCP tool metadata mutates after three legitimate calls (Deadbugz), llms.txt directives point at unregistered names (Alon Hertz). The malicious behavior happens after the review — when the agent's process reads a config file, spawns a subprocess, or writes into .ssh, .aws, or .cursor.

That is where the boundary still holds: watching what an agent's process is about to do, from outside the agent, at the OS. A git status in a freshly-cloned repo that spawns an outbound network call. A "text formatter" MCP tool whose third invocation walks ~/.ssh. An npx <package> from an llms.txt directive resolving to an unregistered domain. Those calls have no benign explanation, and they should be stopped at the syscall.

Google's contribution is the naming. UNC6780 is a real actor, running real campaigns against real AI coding tooling. The review layer has already been budgeted for; the process-behavior layer, at the machine level, has to close.

Sources


SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.