Find notable cyber news and cases, enriched with sources, timelines, and signals.

UNC6780 open-source software supply chain campaign targeting AI environments

Campaign
First reported
Last updated
Happening score
H score 45
2 unique sources, 2 articles

Summary

Hide ▲

UNC6780 is running a large-scale open-source supply-chain campaign that targets AI-assisted coding tools and software dependencies across PyPI, npm, and Docker Hub. GTIG says the group uses Dustmaker to extract tokens from GitHub Actions runners, publish compromised packages that pass automated trust checks, and plant or modify files in hidden workspace directories used by AI coding assistants. The operation also collects credentials to AI tools for resale, increasing downstream exposure for developers and teams that rely on these environments.

Related Happenings

AIR Security launches AIR firewall for enterprise AI-agent supply chains

Security Tool/Service
H score18 First: 03.09.2026 15:00 Last: 03.09.2026 15:00 Sources 1

About this happening: AIR Security emerged from stealth with AIR, a firewall for AI agents that evaluates add-ons before and after deployment to reduce supply-chain risk. The product target...

AIR Security emerges from stealth with $50 million funding and AIR firewall

Commercial Activity
H score18 First: 03.09.2026 15:00 Last: 03.09.2026 15:00 Sources 1

About this happening: AIR Security has emerged from stealth with $50 million in funding and the launch of AIR, a firewall built for AI agents. The rollout expands the market for agent s...

Google CodeMender becomes a fully managed enterprise AI code security agent in Google Cloud

Security Tool/Service
H score12 First: 22.07.2026 13:30 Last: 22.07.2026 13:30 Sources 1

About this happening: Google CodeMender has moved from research into a fully managed enterprise AI code security agent inside Google Cloud, expanding automated vulnerability discovery and r...

FakeGit GitHub lure campaign

Campaign
H score32 First: 20.07.2026 21:23 Last: 20.07.2026 21:23 Sources 1

About this happening: The FakeGit campaign is a GitHub lure operation using nearly 7,600 malicious repositories to distribute SmartLoader and StealC through copied projects, lookali...

Latest development: 22.07.2026 01:34

Island said FakeGit expanded into more than 1,400 repositories tied to AI tools, agents, and workflows, while public registries and catalogs surfaced more than 600 skills and MCP server listings linked to the campaign. The lure set used AgentBaiting to increase visibility to AI agents, and controlled tests showed ChatGPT, Gemini, Claude, and Claude Code could surface or clone malicious repositories and download files before stopping.

Capital One open-sources VulnHunter AI security tool

Security Tool/Service
H score14 First: 20.07.2026 13:25 Last: 20.07.2026 13:25 Sources 1

About this happening: Capital One has released VulnHunter as open source, widening access to an AI-powered security tool built to find and fix code-level vulnerabilities. The tool depar...

Timeline

  1. 08.09.2026 15:02 3 articles · 21h ago

    UNC6780 targets AI environments in open-source supply-chain compromises

    Initial Disclosure

    Google Threat Intelligence Group (GTIG) says AI-assisted coding tools have become a primary target for threat actors, and it identifies UNC6780 as a financially motivated group conducting large-scale open source software supply chain compromises across PyPI, npm, and Docker Hub. The group uses Dustmaker to extract tokens from GitHub Actions runners, publish compromised package versions that pass AI coding automated trust checks, drop or modify malicious files in hidden project workspace directories for AI coding assistants, and collect credentials to AI tools for resale.

    Show sources