Google Names the Agentic Supply-Chain Actor
On September 8, Google's Threat Intelligence Group published a report that turned "threat actors using AI agents to compromise the software supply chain" from a forecast into a named actor, a named campaign, and a named clock: thousands of third-party credentials, harvested end-to-end, in under six hours.
The report is GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI, with same-day coverage from The Hacker News, SiliconANGLE, and Infosecurity Magazine. The Cloud Security Alliance research note on TeamPCP tracks the same actor through prior open-source-supply-chain campaigns.
The named actor
GTIG now tracks the group as UNC6780 — publicly known as TeamPCP, a financially motivated actor GTIG describes as "the most prolific active adversary targeting the software development supply chain" since early 2026. Two attributions matter:
- The initial access shape is upstream, not downstream. Per GTIG, UNC6780 does not attack target organizations directly. It compromises the open-source security and developer tooling those organizations already run, and then harvests the elevated secrets that CI/CD pipelines have to hold to function. The ecosystems named are PyPI, npm, and Docker Hub.
- The AI-agent tooling is a first-class target, not a bystander. UNC6780 publishes trojanized forks of legitimate MCP servers through compromised developer accounts, and — per Infosecurity Magazine's coverage — uses prompt injection to influence how AI coding assistants and LLM-based security scanners analyze the malicious code before it is merged.
The named malware
Two credential stealers appear by name in the tracker, one succeeding the other:
- SANDCLOCK — used in March and April 2026. Python. Linux target. Container-escape functionality. Interacts with Kubernetes. Targets cryptocurrency wallets alongside cloud and developer credentials. GTIG describes it as a component of the campaign publicly referred to as CanisterWorm.
- DUSTMAKER — used from April 2026 onward. Cross-platform JavaScript payload optimized for CI/CD pipelines. No container escape. Focused on credential theft to enable extortion. Per KELA Cyber's profile, Dustmaker extracts GitHub Actions tokens from process memory, publishes trojanized packages that pass AI-driven trust checks, and drops malicious files into hidden IDE/AI-assistant directories:
.claude,.cursor,.vscode.
Those directories are the working state of an AI coding agent. A file that lands there is one the next agent session will read.
The named clock
The number that made the tier-1 headlines is this one: in Q2 2026, GTIG observed a threat actor compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential-harvesting campaign, thousands of credentials wide, in under six hours.
The classical incident-response window — hours to detect, triage, and contain — assumes an attacker taking days between steps. When reconnaissance, tool-building, and execution loops run inside an agent, the outer loop compresses into a single shift. Google's companion post says it directly: "human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond."
Why this one matters
Three claims land at named-vendor, named-actor, named-window resolution — and only one of them was public at this fidelity yesterday:
- The trojanized-MCP-server vector now has an actor. GhostSplice (Aug), Splunk MCP CVE-2026-76404, IBM Langflow MCP CVE-2026-12940, Context7 CVE-2026-75130, and Pillar's Deadbugz campaign each named the pattern. GTIG's tracker is the first tier-1 report to attribute an active, financially motivated actor to the class, with prior campaigns against PyPI, npm, and Docker Hub.
- Attacks on AI coding assistants are running from both sides at once. UNC6780 attacks the assistants (trojanized MCP servers,
.claude/.cursor/.vscodedrops, prompt injection against LLM scanners) and uses assistants to accelerate its own operations. The same substrate that lets an agent read a repo lets an attacker deliver a directive to it. - The response window is a business day, not a work week. "Detect, contain, remediate" inside an AI-agent host now has to run at the attacker's agent cadence, not a human analyst's.
What actually catches this
The GTIG report describes a threat that already defeats pre-approval review — trojanized packages pass AI trust checks (Dustmaker), MCP tool metadata mutates after three legitimate calls (Deadbugz), llms.txt directives point at unregistered names (Alon Hertz). The malicious behavior happens after the review — when the agent's process reads a config file, spawns a subprocess, or writes into .ssh, .aws, or .cursor.
That is where the boundary still holds: watching what an agent's process is about to do, from outside the agent, at the OS. A git status in a freshly-cloned repo that spawns an outbound network call. A "text formatter" MCP tool whose third invocation walks ~/.ssh. An npx <package> from an llms.txt directive resolving to an unregistered domain. Those calls have no benign explanation, and they should be stopped at the syscall.
Google's contribution is the naming. UNC6780 is a real actor, running real campaigns against real AI coding tooling. The review layer has already been budgeted for; the process-behavior layer, at the machine level, has to close.
Sources
- Google Cloud — GTIG AI Threat Tracker: From Prompting to Autonomy
- Google Cloud — Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access
- The Hacker News — Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
- SiliconANGLE — Google says attackers used AI agents to steal credentials in under six hours
- Infosecurity Magazine — AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
- Cloud Security Alliance — TeamPCP (UNC6780): AI Developer Supply Chain's Most Active Threat Actor
- KELA Cyber — TeamPCP (UNC6780): Threat Actor Profile
- Gurucul — TeamPCP Threat Actor Profile: Tactics, Malware & Campaigns
- TechNode Global — Google warns of agentic AI in cyberattacks
SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.