Most Critical Detection 2026 – AI Coding Assistant Supply Chain Compromise (DUSTMAKER / UNC6780)

Detects the creation of potential hook or startup scripts within hidden AI coding assistant directories (.claude, .vscode, .cursor) followed by the execution of a process from those same directories. This pattern is consistent with supply chain compromises where trojanized extensions or MCP servers are leveraged for code execution.