hacker-news · Crawled Sep 8, 2026
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
2 IoCs 1 Actors
Read original article ↗
AI Summary
A financially motivated threat actor known as TeamPCP (aka Altered Spider, UNC6780) has conducted large-scale software supply chain attacks targeting PyPI, npm, and Docker Hub, deploying credential stealers SANDCLOCK and DUSTMAKER. SANDCLOCK, used in March and April 2026, is a Python-based tool targeting Linux and Kubernetes environments with container escape capabilities, while DUSTMAKER is a cross-platform JavaScript payload focused on credential theft in CI/CD pipelines and includes AI-targeting techniques like prompt injection. The group exfiltrates API credentials and targets AI coding assistants, monetizing access through ransomware and data theft extortion networks.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 2 extracted
MITRE ATT&CK TTPs 16 techniques
T1005 Data from Local System · Collection T1036.005 Match Legitimate Name or Location · Defense Evasion T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1081 T1081 T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1133 External Remote Services · Persistence T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1548.001 Setuid and Setgid · Privilege Escalation T1553 Subvert Trust Controls · Defense Evasion T1566 Phishing · Initial Access