Product1 publisher3 min readPublished
A human broke in and assembled the framework, and after that the scanning, the retries and the address rotation ran on their own out of the victim's own IPs. That middle stretch is what response clocks have to survive.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
A developer's working directory collects hidden folders nobody opens on purpose. Google's report puts the DUSTMAKER credential stealer's output in exactly those, directories such as .claude and .cursor, where AI tooling reads the dropped files as ordinary developer clutter [9]. Nothing autonomous is needed for that to work. It works because the assistant's own file conventions create a place where a stray file is unremarkable.
The six-hour case runs on a different mechanism. Mandiant's suspected financially motivated actor got into the cloud infrastructure first, then built the framework out of an AI coding chatbot, a prompt and a set of agent instructions, with preconfigured markdown playbooks driving the scanning and harvesting [3][4]. The autonomy sat in the middle of the chain: troubleshooting and IP rotation ran with no operator, and because traffic left from the victim's own addresses it looked legitimate on the way out [5]. Take thousands at its lowest honest reading, 2,000, and under six hours as under 360 minutes, and the floor is roughly five and a half credentials a minute, retries included [1].
Two GTIG statements sit side by side. John Hultquist's warning is that criminals will gravitate to attacks faster than defenders can respond [15]. The report also says GTIG has not observed fully autonomous attack pipelines deployed against targets in the wild [7], and the closest attempt, a suspected China-linked group designing an automated penetration testing framework with Gemini, never got past trying to build it before Google disabled the assets [8]. So initial access still runs at human pace, while everything after it no longer has to.
The delivery side has been busy in parallel. UNC6780, which Google also tracks as TeamPCP, poisoned the LiteLLM gateway in March and has since pushed trojanized forks of Model Context Protocol servers across PyPI, npm and Docker Hub while injecting malicious code into GitHub repositories that AI coding assistants clone [10][11]. That is four distribution paths terminating on a developer machine [2]. Some loaders carry prompt injections phrased as extreme biological and nuclear weapons requests, apparently so that an LLM security scanner refuses the file and never reads the malicious JavaScript underneath [12]. Credential hygiene is the same story one layer down: an exposed GitHub token was enough for an attacker to provision high-performance GPU instances in April on a victim's bill [16].
For whoever is rolling out a coding assistant, two properties decide the exposure, and neither appears on the pricing page. First, what the tool can read from the filesystem without being asked. Second, what it can execute or fetch without a human approving. Broad read with approval required is a theft problem, and DUSTMAKER is the shape of it [9]. Broad read with no approval is the shape of the six-hour campaign. Narrow read with no approval is the tolerable half of the automated pair, and it is the configuration that takes real work to arrange.
Which quadrant actually hurts depends on the gap between an assistant acting and a human looking. On an eight-hour shift, a campaign that completes in under six leaves more than two hours before the shift is even over [3]. If the queue gets triaged the following morning, the artifact the team produces is a post-mortem.
Ranked by verification strength, evidence, and original report placement.
Google Threat Intelligence Group said in a report released today that threat actors used a multi-agent artificial intelligence framework to compromise thousands of credentials in under six hours.
The report, titled "From Prompting to Autonomy: The Evolution of Adversarial AI", covers activity GTIG tracked over the second quarter.
Mandiant investigators traced the campaign to a suspected financially motivated actor that first broke into an organization's cloud infrastructure.
The attacker assembled an autonomous framework out of an AI coding chatbot, a prompt and a set of agent instructions, with preconfigured markdown playbooks driving the scanning and harvesting that followed.
Troubleshooting and IP rotation ran without an operator, and traffic left the victim's own addresses, so it looked legitimate on the way out.
The May edition of the report documented the first confirmed case of criminals using AI to build a working zero-day exploit; GTIG said what has changed since then is how little human involvement is left, with adversaries handing multistep decisions to models, which shrinks the window defenders have to react.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor report, one relay
Every fact carrying weight here traces to Google's own quarterly report, retold by SiliconANGLE with no second party checking it. The report is specific in ways that could be checked later: actor designators, a named stealer, a named gateway compromise, dated incidents, and an analyst willing to be quoted by name. A defender trying to verify any of it would still need the credential count and the identity of the coding chatbot involved, and neither one made it into the account.
Several incidents inside one quarter
Attacker uptake is documented rather than projected: a completed credential harvest, sustained publishing runs across three package ecosystems plus cloned repositories, an April GPU hijack, and several extortion cases involving model IP. The ceiling is set by Google's own limits — the one attempt at a self-running intrusion framework failed and was cut off, and GTIG says it has yet to see a fully autonomous pipeline used against a target.
Autonomy overstated by one degree
"Attackers used AI agents to steal credentials" is the headline; the body says a person broke into the cloud environment and assembled the framework, after which the scanning and rotation ran unattended. That middle stretch is genuinely unattended and genuinely fast, so the overstatement is modest rather than invented, and SiliconANGLE does keep GTIG's caveat that nobody has seen an end-to-end autonomous pipeline in use. The looseness that inflates it most is quantitative: "thousands" carries whatever weight the reader gives it.
Finder, vendor and abused platform are one company
Google found the activity, tracks the actors, sells the threat intelligence and the security products, and owns Gemini, the model an espionage group tried to build a penetration testing framework with. A quarterly report arguing that adversaries are outpacing defensive response supports all of those lines at once, and this reporting does not weigh that. On the publishing side, SiliconANGLE closes with its own community and marketplace funnel, which colors volume rather than substance.
Moderate, pending corroboration
The technical detail is falsifiable enough that a second researcher could confirm or dent it — .claude and .cursor drop paths, the LiteLLM poisoning, the UNC designators — and the caveats Google keeps in cut against easy alarm, which is a mark in its favor. Against that: one publisher, one document, undisclosed victim counts, and dated months without years attached to the March and April incidents.
build
Every one of thirteen named 2025-26 incidents ran on a credential that still worked1 publisher
security
A free Artifactory plugin can hold npm and PyPI versions until they age in public1 publisher
security
Malicious litellm PyPI releases tied to Trivy scan dependency bypassed official CI/CD1 publisher
build
Pandex hooked a Fortune 500 agent four minutes after claiming a package name from llms.txt1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 8, 2026