Undercover Google Agent Infiltrated TeamPCP's Supply Chain Hacking Spree
A recent revelation from **Google's Threat Intelligence Group** details an unprecedented infiltration of the notorious hacker group **TeamPCP**. An undercover **Mandiant** analyst was embedded within the group's inner circle, providing crucial intelligence that helped disrupt their extensive software supply chain attack campaign and ultimately led to the arrest of key members.
Before the recent arrests of two alleged members in Australia, the hacker group known as **TeamPCP** orchestrated a hacking spree of unprecedented scale. Their campaign involved tainting hundreds of open-source programs with malware, hijacking developer accounts for further supply chain compromises, and even deploying a **Dune**-themed self-spreading worm named **Mini Shai-Hulud** to automate their attacks. This ultimately led to the breach of over a thousand companies.
Now, **Google's Threat Intelligence Group** has disclosed that during a critical phase of **TeamPCP's** rampage, one of their undercover researchers had infiltrated the group. This allowed **Google** to monitor the hacking spree from the inside, issue warnings to breach targets, and actively disrupt the group's attempts to exploit victims.
### The TeamPCP Mole
**Austin Larsen**, a researcher with **Google's Threat Intelligence Group**, presented the full details of this investigation and infiltration at **SentinelOne's LABScon** research conference. According to Larsen, **Google** eventually traced operational security blunders made by one of the two Australians now accused of being leading **TeamPCP** members, sharing key identifying details with law enforcement.
Further intelligence was also provided by **ShinyHunters**, another infamous cybercriminal group that initially partnered with **TeamPCP** but later turned on them. Most surprisingly, Larsen revealed that **Google's** security subsidiary **Mandiant** had an undercover analyst within **TeamPCP's** inner circle almost from the beginning of their public activity.
"One of our personas had been working for many months to build trust with one of the actors that was invited to join **TeamPCP**, and so was added to the group," Larsen told WIRED. "So essentially, almost day one, **Mandiant** was watching everything behind the scenes."
### Arrests and Extensive Compromises
Late last month, **Ruben Ian Thomson** and **Louis Michael Gaebler**, both in their early twenties from Australia, were arrested by Australian police in a joint operation with assistance from the **FBI**. They were charged with hacking crimes and described by the **Australian Federal Police (AFP)** as "principal participants" in **TeamPCP**.
**TeamPCP**, which first appeared online in late 2025, gained notoriety for its audacious string of cascading supply chain attacks. They repeatedly compromised open-source software to embed malware, subsequently hijacking developer credentials to plant malicious code in other widely used tools, creating a continuous cycle of compromise.
Beginning this spring, **TeamPCP** compromised the open-source security scanner **Trivy**, the AI application programming interface tool **LiteLLM**, infrastructure belonging to web application security firm **Checkmarx**, the web app library **TanStack**, and the enterprise AI platform **Mistral AI**. These successive supply chain attacks enabled the group to expand its reach, ultimately breaching **GitHub**, data contracting firm **Mercor**, and employee devices at **OpenAI**, the **European Commission**, and numerous other unnamed entities.
In March, as **TeamPCP's** supply chain hacking intensified, **Google's** undercover analyst was invited into the hackers' inner circle, gaining access to **CanisterWorm**, a core chat comprising about 12 members. "You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history," one **TeamPCP** member reportedly wrote in the leaked chats.
### Disrupting the Campaign
**Google's** undercover analyst also gained access to a server where **TeamPCP** stored its vast trove of stolen credentials, including usernames, passwords, and access tokens. This intelligence prompted **Google's** team to act swiftly to warn victims and thwart **TeamPCP's** extortion schemes.
Rather than directly alerting individual victims, which would have been too time-consuming given the sheer volume of compromised companies, **Google** prioritized contacting providers like **Amazon Web Services** and **Microsoft** to revoke the stolen credentials. Larsen and his team sent hundreds of notification emails to these providers and subsequently to victims, receiving immediate responses in many cases.
Around the same period, **Google's** visibility into the **TeamPCP** internal chat revealed that a core member was developing a zero-day exploit using an AI tool. This exploit aimed to bypass two-factor authentication in a widely used login software. **Google's** team obtained the exploit code, confirmed its functionality with minor adjustments, and promptly warned the software's developer, who was able to patch the vulnerability. This incident, detailed in a May case study by **Google** (without naming **TeamPCP** or the exploit's source), marks a rare instance of an AI-created hacking technique exploiting a previously unknown flaw.
### Betrayals and Sloppy OpSec
It turns out **Google's** analyst wasn't the only 'traitor' within **TeamPCP**. Despite accumulating over half a million user credentials, according to the **AFP**, the group struggled to monetize its stolen data, reportedly only earning tens of thousands of dollars in extortion payments, far less than similar groups.
To improve monetization, **TeamPCP** partnered with other cybercriminal groups, granting them access to stolen credentials in exchange for a percentage of any extortion payments. One such partner was **ShinyHunters**, a prolific group known for multi-million dollar data theft and ransomware operations, including the breach of educational software platform **Canvas**.
Around April, a few weeks after partnering with **TeamPCP**, **ShinyHunters** went rogue. They conducted their own extortions using **TeamPCP's** credentials without sharing the agreed-upon cut. **ShinyHunters** even unsolicitedly shared a full log of **TeamPCP's** server chat with Larsen, unaware that **Google** already had internal access through its embedded mole.
