An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang

Before the Australian Federal Police (AFP) executed a series of raids last month that dismantled the core of the hacker collective known as TeamPCP, the group had already cemented its place in the annals of cyber warfare. By orchestrating a sophisticated, multi-layered supply chain attack, TeamPCP managed to compromise hundreds of open-source software packages, hijack high-level developer accounts, and deploy an automated, self-spreading worm that terrorized the software development ecosystem. The breadth of their operations, which breached over a thousand organizations ranging from small startups to global entities like OpenAI and the European Commission, marked a distinct shift in how cybercriminal organizations weaponize the trust inherent in the open-source community.
However, as Google’s Threat Intelligence Group (TIG) has now revealed, the group’s meteoric rise was shadowed by a silent observer. For months, an undercover analyst working for Mandiant—Google’s security subsidiary—had successfully integrated themselves into the inner circle of TeamPCP, gaining a front-row seat to one of the most audacious hacking campaigns in recent history.
The Anatomy of a Supply Chain Heist
The methodology employed by TeamPCP was both brazen and highly technical. Rather than targeting individual companies directly, which is often resource-intensive and prone to detection, the group targeted the foundations of the software industry. By compromising widely used open-source libraries—such as the security scanner Trivy, the AI API tool LiteLLM, and the web app library TanStack—TeamPCP turned the tools developers rely on into vectors for malicious code.
Once an open-source project was tainted, the malware would automatically scrape the credentials of developers interacting with the code. These stolen access tokens and passwords served as "keys to the kingdom," allowing the hackers to escalate their access and move laterally into corporate environments. This cascading effect, where one compromise facilitated a dozen more, created a self-sustaining cycle of exploitation.
The group’s efficiency was further bolstered by the deployment of a custom-built worm dubbed "Mini Shai-Hulud." Named after the legendary sandworms of Frank Herbert’s Dune, the worm was designed to automate the identification and exploitation of vulnerable systems. The existence of this tool underscored a shift toward industrialized, automated cybercrime, where human hackers acted more as architects of a machine-driven exploitation engine.

Chronology of the Infiltration
The story of the mole begins in early 2025, when TeamPCP first surfaced on the radar of international cybersecurity researchers. Recognizing the potential threat, Mandiant initiated a long-term intelligence-gathering operation. By March 2025, their undercover researcher had successfully cultivated a persona trusted by the group’s recruiters, eventually receiving an invitation to "CanisterWorm," a private chat server restricted to the inner circle of approximately 12 members.
From this vantage point, Google’s analyst provided actionable intelligence that prevented countless breaches. As the campaign intensified, the intelligence gathered allowed Google to bypass the traditional, slow process of notifying individual victims. Instead, the firm collaborated directly with infrastructure providers like Microsoft and Amazon Web Services to revoke stolen credentials before they could be used, effectively neutralizing the hackers’ leverage in real-time.
By April, the internal power dynamics of TeamPCP began to shift. Seeking to maximize the monetization of their massive database—which allegedly contained over 500,000 sets of user credentials—the group attempted to partner with other notorious entities, including the infamous cybercriminal collective ShinyHunters. This move proved to be their undoing. ShinyHunters, notorious for the massive breach of the educational platform Canvas, betrayed their partners, stealing credentials and even sharing internal logs of TeamPCP’s communications with security researchers, unaware that Google already possessed its own direct line into those systems.
The Fall of the Principals
The collapse of TeamPCP was accelerated by a combination of high-level intelligence and elementary operational security (opsec) failures. As Austin Larsen, a lead researcher at Google Threat Intelligence Group, detailed during a presentation at the LABScon research conference, the group’s leaders—identified as Ruben Ian Thomson and Louis Michael Gaebler—left a digital trail that was difficult to ignore.
Larsen’s team traced a key handle in the CanisterWorm chat to an email address, [email protected], which had been linked to a 2019 dispute over pirated software on a hacker forum. The trail grew hotter when it was discovered that the group was backing up their stolen, illicit data to a Google Drive account associated with that same email address. This oversight allowed Google to provide the FBI with concrete evidence, leading to the rapid issuance of warrants and the subsequent arrests in Australia.
In late August 2026, the Australian Federal Police, with assistance from the FBI, moved in. Video footage released by the authorities showed the arrest of a 21-year-old suspect in a quiet suburban home, a stark contrast to the sophisticated digital warfare being conducted from the same residence.

Implications for Modern Cybersecurity
The saga of TeamPCP serves as a cautionary tale regarding the fragility of the global software supply chain. The incident highlights several critical areas where the current security model is failing:
- Trust-Based Vulnerabilities: The reliance on open-source code is a double-edged sword. While it fosters innovation, it also provides a massive attack surface for threat actors who can inject malicious code into trusted, widely used repositories.
- The Rise of Offensive AI: Google’s discovery that TeamPCP was using AI tools to develop zero-day exploits specifically designed to bypass two-factor authentication (2FA) is a harbinger of a new era. The automation of vulnerability research means that the time between a patch being needed and an exploit being developed is shrinking rapidly.
- The Shift Toward "Disruption": Google’s proactive strategy—the formation of the Cyber Disruption Unit—marks a departure from the traditional, passive role of security firms. Instead of merely issuing warnings, firms are increasingly taking active, sometimes aggressive, steps to dismantle criminal infrastructure.
"Writing reports can only be so useful," Larsen stated during his briefing. "Taking action to protect users and customers—that is the next step."
Official Responses and Future Outlook
The FBI, while declining to comment on specific active investigations, emphasized in a statement that their current strategy relies heavily on private-sector partnerships. This "whole-of-society" approach to cyber defense is increasingly viewed as the only viable way to combat agile, decentralized hacker groups.
The legal proceedings for Thomson and Gaebler are expected to be lengthy, as authorities work to untangle the web of international victims and assess the full scope of the stolen data. For the companies that were targeted, the incident has prompted a widespread audit of their internal software development lifecycles (SDLC) and a renewed focus on vetting third-party dependencies.
As the dust settles, the TeamPCP case will likely be studied for years to come. It represents a rare victory for defenders, not because of a single defensive wall, but because of a human presence inside the enemy’s camp. Yet, it also underscores a sobering reality: as long as there is value in the data stored on our networks, the supply chain will remain the primary target, and the race between those who build our digital world and those who wish to exploit it will only continue to accelerate.







