hacker-news · Crawled Sep 8, 2026

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

2 IoCs 1 Actors
Read original article ↗

AI Summary

A financially motivated threat actor known as TeamPCP (aka Altered Spider, UNC6780) has conducted large-scale software supply chain attacks targeting PyPI, npm, and Docker Hub, deploying credential stealers SANDCLOCK and DUSTMAKER. SANDCLOCK, used in March and April 2026, is a Python-based tool targeting Linux and Kubernetes environments with container escape capabilities, while DUSTMAKER is a cross-platform JavaScript payload focused on credential theft in CI/CD pipelines and includes AI-targeting techniques like prompt injection. The group exfiltrates API credentials and targets AI coding assistants, monetizing access through ransomware and data theft extortion networks.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
Filename SANDCLOCK Details →
Filename DUSTMAKER Details →

MITRE ATT&CK TTPs 16 techniques