Find notable cyber news and cases, enriched with sources, timelines, and signals.

UNC6780 open-source software supply chain campaign targeting AI environments

Campaign
First reported
Last updated
Happening score
H score 45
2 unique sources, 2 articles

Summary

Hide ▲

UNC6780 is running a large-scale open-source supply-chain campaign that targets AI-assisted coding tools and software dependencies across PyPI, npm, and Docker Hub. GTIG says the group uses Dustmaker to extract tokens from GitHub Actions runners, publish compromised packages that pass automated trust checks, and plant or modify files in hidden workspace directories used by AI coding assistants. The operation also collects credentials to AI tools for resale, increasing downstream exposure for developers and teams that rely on these environments.

Related Happenings

China-based AI labs illicit Claude distillation campaign

Campaign
H score27 First: 11.09.2026 19:15 Last: 11.09.2026 19:15 Sources 1

About this happening: A coordinated industrial-scale distillation campaign against Claude is extracting reasoning and tool-use outputs to train competing models, increasing the risk of unauthor...

Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration

Technical Analysis
H score59 First: 11.09.2026 17:29 Last: 11.09.2026 17:29 Sources 1

About this happening: Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, recon...

China-based AI companies' knowledge-distillation campaign against U.S. frontier AI models

Campaign
H score23 First: 08.09.2026 15:00 Last: 08.09.2026 15:00 Sources 1

About this happening: Anthropic said it disrupted industrial-scale illicit distillation against Claude by seven China-based labs, including Alibaba, Moonshot, DeepSeek, Z....

AIR Security launches AIR firewall for enterprise AI-agent supply chains

Security Tool/Service
H score18 First: 03.09.2026 15:00 Last: 03.09.2026 15:00 Sources 1

About this happening: AIR Security emerged from stealth with AIR, a firewall for AI agents that evaluates add-ons before and after deployment to reduce supply-chain risk. The product target...

AIR Security emerges from stealth with $50 million funding and AIR firewall

Commercial Activity
H score18 First: 03.09.2026 15:00 Last: 03.09.2026 15:00 Sources 1

About this happening: AIR Security has emerged from stealth with $50 million in funding and the launch of AIR, a firewall built for AI agents. The rollout expands the market for agent s...

Timeline

  1. 08.09.2026 15:02 3 articles · 13d ago

    UNC6780 targets AI environments in open-source supply-chain compromises

    Initial Disclosure

    Google Threat Intelligence Group (GTIG) says AI-assisted coding tools have become a primary target for threat actors, and it identifies UNC6780 as a financially motivated group conducting large-scale open source software supply chain compromises across PyPI, npm, and Docker Hub. The group uses Dustmaker to extract tokens from GitHub Actions runners, publish compromised package versions that pass AI coding automated trust checks, drop or modify malicious files in hidden project workspace directories for AI coding assistants, and collect credentials to AI tools for resale.

    Show sources