Google Warns AI Coding Tools Are Now a Top Target for Cybercriminals
Google Threat Intelligence Group (GTIG) has warned that AI-assisted coding tools have become a prime target for cybercriminals, contributing to several large-scale software supply chain compromises in 2025 and early 2026. As businesses rapidly adopt AI models into their development processes, the growing use of supporting resources like model context protocol (MCP) servers has expanded the attack surface. GTIG also noted that faster AI-driven development has likely reduced scrutiny of third-party code and dependencies.
A financially motivated group tracked as UNC6780 has been actively exploiting this trend, targeting open-source ecosystems such as PyPI, npm, and Docker Hub. Using malware known as Dustmaker, the group steals credentials from AI environments and developer tools, sometimes by extracting tokens from GitHub Actions processes or hiding malicious files within AI coding assistant directories to avoid detection. Stolen credentials are then sold to other cybercriminal groups.
GTIG cautioned that the success and public release of UNC6780's tools will likely inspire copycat attacks. The report also notes a wider trend of threat actors, including state-sponsored groups, targeting proprietary AI systems used across government, military, and healthcare sectors.