An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Google’s threat‑intelligence arm has just dropped a bombshell on the cyber‑crime scene: a Mandiant analyst slipped into the inner circle of the notorious supply‑chain hacking collective TeamPCP almost from day one.

Sep 20, 2026 - 16:03
0 3
An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Google’s threat‑intelligence arm has just dropped a bombshell on the cyber‑crime scene: a Mandiant analyst slipped into the inner circle of the notorious supply‑chain hacking collective TeamPCP almost from day one. The covert operation let Google watch the group’s unprecedented campaign from the inside, tip off victims, and even help derail a few of its most dangerous moves. The revelation, delivered by researcher Austin Larsen at SentinelOne’s LABScon conference on 20 September 2026, shines a light on how a single operational‑security slip can open a backdoor for the world’s biggest defenders.

How TeamPCP rewrote the supply‑chain playbook

First spotted online in late 2025, TeamPCP quickly earned a reputation for “a hacking spree unlike any other in history.” Its playbook combined classic supply‑chain tactics—poisoning open‑source projects and hijacking developer accounts—with a self‑spreading worm dubbed Mini Shai‑Hulud, a nod to the sandworms of *Dune*. By the time Australian authorities moved in last month, the gang had tainted “hundreds of open‑source programs,” breached more than a thousand companies, and slipped into high‑profile targets such as GitHub, OpenAI, the European Commission, and a data‑contracting firm called Mercor.

The group’s modus operandi was a relentless loop: compromise a popular tool, embed malicious code, harvest the credentials of its maintainers, and use those keys to infiltrate the next layer of the software ecosystem. Early‑2026 attacks on the security scanner Trivy, the AI API toolkit LiteLLM, Checkmarx’s infrastructure, the TanStack library, and the enterprise AI platform Mistral AI illustrate how each foothold fed the next, creating a cascading effect that amplified the reach of their malware.

Google’s inside man: a Mandiant analyst in the chatroom

According to Larsen, the infiltration began in March 2026, when a Mandiant operative—identified only as “one of about 12 members” with access to the core TeamPCP chat called CanisterWorm—joined the hackers’ inner circle. “One of our personas had been working for many months to build trust… and so was added to the group,” Larsen told WIRED ahead of his LABScon talk. This early foothold meant Google could monitor the gang’s chatter from almost the outset of its high‑profile spree.

The analyst’s presence gave Google a front‑row seat to the group’s tactics, including a trove of stolen credentials stored on a shared server. By seeing exactly which usernames, passwords, and access tokens the gang had harvested, Google could act quickly—targeting the infrastructure where those credentials would be used rather than trying to notify every compromised organization individually.

The chase: operational mistakes that led to arrests

TeamPCP’s downfall, as Larsen explained, hinged on a series of operational‑security blunders by its Australian members. The two suspects—Ruben Ian Thomson and Louis Michael Gaebler, both in their early twenties—were arrested in Australia last month after a joint investigation with the FBI. The Australian Federal Police (AFP) described them as “principal participants” in a press release that, due to privacy law, omitted their names.

Google passed the identifying details it gathered from the insider’s access to law‑enforcement partners, helping to piece together the link between the leaked chats and the two Australians. Their arrests underscore how even sophisticated cyber‑crime outfits can be undone by simple slip‑ups, especially when a well‑placed defender is watching.

Turning intel into action: disrupting the credential theft pipeline

Armed with a live view of the stolen‑credential cache, Google opted for a pragmatic disruption strategy. Rather than alert each victim directly—a process that would have been too slow given the scale—the company reached out to cloud providers like Amazon Web Services and Microsoft, urging them to revoke the compromised keys. “We sent out hundreds of notification emails to those providers and then to victims, many of which got immediate responses,” Larsen said.

This rapid revocation forced TeamPCP to scramble for fresh access, buying time for the victims to shore up defenses. The approach illustrates a shift from reactive breach notification to proactive credential invalidation, a tactic that could become standard when defenders have inside visibility.

The AI‑crafted zero‑day: a rare glimpse of machine‑generated exploits

One of the most striking discoveries from the CanisterWorm monitor was an AI‑generated zero‑day exploit targeting a widely used login platform. A group member, separate from the supply‑chain attacks, was using an AI tool to craft a novel bypass for two‑factor authentication. Google’s team snagged the exploit code, tested it, and confirmed it worked with only minor tweaks.

After alerting the software’s developer, a patch was rolled out, neutralizing the vulnerability before it could be weaponized at scale. This episode marks one of the few documented cases where an AI‑produced exploit was caught in the wild, highlighting the emerging threat of machine‑assisted hacking and the value of inside intelligence to pre‑empt such attacks.

Allies and betrayals: the role of ShinyHunters

TeamPCP’s operations were not conducted in isolation. The group partnered with another notorious cyber‑crime outfit, ShinyHunters, to amplify its reach. However, ShinyHunters eventually turned on TeamPCP, providing Google with additional intelligence that helped flesh out the gang’s infrastructure and tactics.

This betrayal underscores the volatile alliances within the underground hacking economy, where today’s partner can become tomorrow’s informant. For defenders, such fractures can be a goldmine, offering insider perspectives that are otherwise impossible to obtain.

What the infiltration means for the broader cyber‑security landscape

The TeamPCP saga demonstrates that even the most sophisticated supply‑chain attackers can be outmaneuvered when defenders embed themselves within the adversary’s command‑and‑control channels. Google’s ability to watch the group’s internal chats, harvest stolen credentials, and intervene with cloud providers turned a massive, chaotic campaign into a series of contained incidents.

For ordinary enterprises, the takeaway is clear: supply‑chain risk is not just a technical problem but a human one. Operational‑security lapses—like reusing credentials or failing to vet new members—can expose organizations to the same chain reaction that TeamPCP exploited. As Google’s inside operation shows, the best defense may sometimes be to get a seat at the table, even if that table belongs to the enemy.

This article was produced with AI-assisted research and editorial support. Reporting is based on the source material cited below. Sources: Ars Technica; arstechnica.com; Global1.News (20 September 2026).

By Nova Chen, Staff Writer

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Nova Chen

Trend Reporter at Global1.News. Based in San Francisco, tracking the stories crossing from social platforms, forums, and community discussions into mainstream news — tech breakthroughs, cultural shifts, and world events that real people are engaging with right now.

Comments (0)

User