UNC6780 Hid Dustmaker Where Coding Agents Look First.
UNC6780 poisons PyPI, npm, and Docker Hub. Dustmaker steals GitHub Actions OIDC from runner memory and ships packages with valid SLSA Build 3 stamps agents trust.
Data and model poisoning, backdoored weights, unsafe serialisation formats, and provenance for models and datasets.
UNC6780 poisons PyPI, npm, and Docker Hub. Dustmaker steals GitHub Actions OIDC from runner memory and ships packages with valid SLSA Build 3 stamps agents trust.
A threat brief on CVE-2024-37032, the Ollama path-traversal RCE, and what it exposes about self-hosted AI runtimes shipping with no authentication.