GTIG Sees AI Tools Speed Supply-Chain Abuse

Google Threat Intelligence Group (GTIG) warned on September 8 that AI-assisted coding tools and the open-source plumbing around them are now a prime target, and tied that shift to large-scale supply-chain compromises in 2025 and early 2026. GTIG highlighted UNC6780, a financially motivated group that has hit PyPI, npm, and Docker Hub. The group steals the same tokens and runner credentials developer automation already trusts, including secrets pulled from GitHub Actions process memory, then uses them to publish tainted packages that still look valid to automated checks. GTIG also said UNC6780 hides malicious files in workspace directories used by AI coding assistants, where the changes blend into developer noise instead of standing out. For teams running AI-assisted development, the exposure sits in the automation account and package pipeline, not in the model itself. If those trust paths can be reused with stolen credentials, a single compromised dependency can move from hidden to widely distributed before normal review catches up.

Part of the PlainSec briefing for 2026-09-08

Every edition of this story: GTIG Sees AI Tools Speed Supply-Chain Abuse

Sources