← Back to Daily Briefing

In Q2–Q3 2026, threat actors shifted from prompt‑based abuse to fully agentic, multi‑framework attacks that compromised AI coding assistants, injected malicious dependencies into MCP servers and .claude/ configs, and leveraged model distillation to harvest >100 M prompts from Gemini and Claude. Trojanized packages on PyPI/npm/Docker Hub delivered credential‑stealing malware (DUSTMAKER) and LLM proxy services, enabling rapid exfiltration of thousands of third‑party API keys and cloud credentials within six hours. PRC‑nexus groups (UNC6508, CALANQUE ION) used hijacked cloud compute to run local LLM instances, evading API monitoring while exfiltrating proprietary model weights and source code. The campaign impacted healthcare, government, media, technology, academic and military sectors across North America, Europe, and Asia, prompting Google and Anthropic to disable assets, update classifiers, and issue mitigation guidance.

  • Incident Overview: AI Model Provider Supply Chain Campaign
  • Compromise vector: trojanized MCP server packages (e.g., tiktoken_mcp, azure-functions-mcp-extension) published via compromised developer accounts.
  • Primary malware: DUSTMAKER credential stealer with hidden directory payloads (.claude/, .vscode/, .cursor/) and OIDC token theft from GitHub Actions.
  • Scope: dozens of malicious packages affecting North American and Asian enterprise CI/CD pipelines.

  • Attack Mechanics & Campaign Flow

  • Agentic vulnerability scanning framework “Recon” automated reconnaissance, dependency injection, and prompt injection to bypass LLM security scanners.
  • Model distillation infrastructure used proxy networks rotating thousands of compromised credentials to harvest >100 M prompts from Gemini and Claude.
  • PRC‑nexus groups employed CC Switch tool to orchestrate multi‑model exploitation pipelines (Claude, Gemini, Codex) and deployed Shai‑Hulud framework for persistent C2 and credential harvesting.

  • Threat Group Profile & Impact

  • Financially motivated UNC6780 monetized stolen API keys and cloud credentials via direct sale and ransomware partnerships.
  • Espionage‑focused UNC6508 and CALANQUE ION exfiltrated proprietary AI research, model weights, and source code; used hijacked cloud compute to run local LLMs to avoid API monitoring.
  • Observed time‑to‑compromise: initial cloud breach to full credential exfiltration in under six hours; thousands of third‑party credentials harvested in a single <6‑hour campaign.

  • Indicators of Compromise & Defensive Actions

  • IoCs: malicious PyPI/npm/Docker Hub packages (names matching tiktoken_mcp, azure-functions-mcp-extension), _index.js prompt‑injected JavaScript loader, AGENTS.md/KNOWLEDGE.md directories, memory/ artifacts, DUSTMAKER C2 domains.
  • Detection: anomalous OIDC token requests from GitHub Actions, unexpected outbound connections to rotating proxy IPs, sudden spikes in LLM API usage patterns indicative of distillation probes.
  • Mitigation: Google disabled compromised assets, updated Gemini safety classifiers, released hardening guidance; Anthropic revoked hijacked Claude accounts, enforced stricter package signing, and published threat‑intelligence report with IOCs.

  • Conclusion & Outlook

  • The campaign demonstrates a convergence of AI‑enabled automation, supply‑chain tampering, and credential theft, elevating AI model providers to both attack vectors and high‑value targets.
  • Organizations must enforce strict provenance checks for AI‑assistant packages, monitor for anomalous credential usage in CI/CD, and deploy LLM‑specific runtime protections against prompt injection and model extraction.
  • Continued threat‑intelligence sharing and model‑level defenses (e.g., robust refusal classifiers, output filtering) are essential to mitigate emerging agentic AI threats.

Related posts

  1. Cycode
  2. thehackernews.com — Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
  3. Computing
  4. cybersecuritydive.com — Threat groups enhance cyberattack capabilities with AI
  5. Anthropic
  6. cyberscoop.com — AI lets small actors run state-level hacking campaigns, Anthropic report finds
  7. Channelinsider
  8. Shattered
  9. Fonearena
  10. Broadbandbreakfast

LINK COPIED TO CLIPBOARD