What Happened
Mandiant describes incidents involving UNC6780, also known as TeamPCP, including theft of AI service credentials and proprietary AI data. The report says the group used prompt injection against AI coding assistants and LLM-based security scanners, demonstrating risks to enterprise development and AI supply chains.
Why It Matters
The Mandiant report describes UNC6780, also known as TeamPCP, stealing AI service credentials and proprietary AI data while compromising open-source software ecosystems. It also reports prompt-injection techniques used against AI coding assistants and LLM-based security scanners, demonstrating how poisoned dependencies and project content can manipulate AI-enabled development workflows. RealGround analysis: organizations should assess AI and software dependencies, inventory supply-chain components, and continuously test assistants and scanners for prompt-injection and data-exfiltration paths.
RealGround Analysis
This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://cloud.google.com/security/resources/ai-risk-and-resilience-2026
