Inside the Inner Circle: How a Google Undercover Analyst Infiltrated the Historic TeamPCP Software Supply-Chain Hacking Spree

The modern landscape of cybercrime is defined not just by raw technical prowess, but by complex webs of collaboration, shifting loyalties, and increasingly aggressive counter-offensive measures taken by private enterprise and law enforcement alike. In what is now recognized as one of the most destructive and chaotic software supply-chain hacking sprees in modern history, the hacker collective known as TeamPCP managed to compromise hundreds of open-source programs, hijack developer accounts, and deploy a self-spreading worm themed after the science-fiction epic Dune. However, the group’s unprecedented run came to an abrupt halt following a coordinated international law enforcement operation in Australia. Behind this takedown lay a startling revelation: Google’s threat intelligence group had successfully planted an undercover analyst deep inside TeamPCP’s inner circle almost from the very beginning of its public campaign.

Details of this deep-cover infiltration were brought to light by Austin Larsen, a researcher with the Google Threat Intelligence Group, during a presentation at the SentinelOne LABScon research conference. The operation highlights an evolving paradigm in cybersecurity, where major tech conglomerates do not merely react to breaches after the fact, but actively penetrate adversarial forums to preempt attacks, trace perpetrators, and disrupt criminal infrastructure before catastrophic damage can occur.

The Rise and Scale of TeamPCP

Emerging on the cybercrime scene in late 2025, TeamPCP quickly established a reputation for audacious and cascading supply-chain attacks. Unlike traditional cyberattacks that target a single enterprise via phishing or direct perimeter breaches, TeamPCP leveraged the interconnected nature of modern software development. By injecting malware into widely used open-source repositories and development tools, the group could automatically harvest credentials, hijack developer accounts, and propagate further intrusions down the line.

The scope of the group’s campaign expanded rapidly through the spring of 2026. TeamPCP compromised critical open-source infrastructure and enterprise platforms, including the security scanner Trivy, the AI application programming interface tool LiteLLM, web application security firm Checkmarx, the web application library TanStack, and the enterprise AI platform Mistral AI. Each successful compromise acted as a force multiplier, casting a wider net that ultimately allowed the hackers to breach open-source code repository GitHub, data contracting firm Mercor, and employee devices at prominent entities such as OpenAI and the European Commission.

Adding a chilling layer of automation to their campaign, the group deployed a malicious worm dubbed Mini Shai-Hulud, named after the colossal sandworms of Frank Herbert’s Dune. This automated propagation tool allowed the group to scale its operations rapidly, breaching more than a thousand companies globally and amassing a treasure trove containing the credentials of over half a million users.

Operation CanisterWorm: The Infiltration

While TeamPCP was executing its sweeping campaign, Google’s Threat Intelligence Group and its Mandiant subsidiary were already watching from the inside. According to Larsen, an undercover analyst had spent months building trust online with an individual who was eventually invited to join TeamPCP. This strategic patience paid off when the Google persona was added to the group’s core chat server, designated as CanisterWorm, which restricted its inner circle to roughly a dozen members.

This access provided Google with unprecedented, real-time visibility into the hackers’ motivations, methods, and internal communications. In one message recovered from the leaked chats, a TeamPCP member boasted, "You guys should understand that we pulled off the biggest supply chain maybe ever recorded in modern history."

The presence of the mole fundamentally altered how security researchers and law enforcement could respond. Rather than playing catch-up after forensic investigations of breached networks, Google’s team had a front-row seat to the group’s logistical operations. Michael Fletcher, a former Australian Federal Police (AFP) analyst currently working in threat research for an Australian telecommunications firm, recalled discussing monitoring strategies with Larsen during the peak of the campaign. Fletcher was stunned to learn that Google had already embedded an operative within the group early on, effectively neutralizing the hackers’ operational security advantages from day one.

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Disruption Tactics and AI-Driven Threats

With direct visibility into the server where TeamPCP stored its massive trove of stolen credentials, Google faced a tactical dilemma: how to neutralize the threat before the hackers could successfully monetize their breaches through extortion. Alerting every individual victim organization directly would have been a protracted process that could have tipped off the hackers and accelerated their ransom demands.

Instead, Google adopted a triage approach. The threat intelligence team bypassed individual user notifications initially, opting instead to contact major cloud and identity service providers—such as Amazon Web Services and Microsoft—where the stolen credentials were most likely to be utilized. By having these platforms rapidly revoke compromised tokens and credentials, Google effectively blunted TeamPCP’s ability to access targeted environments. Hundreds of notification emails were dispatched to infrastructure providers and subsequently to affected corporations, triggering immediate defensive responses.

Furthermore, Google’s vantage point within the CanisterWorm chat uncovered a novel and alarming development: the intersection of generative artificial intelligence and offensive cyber operations. Monitoring revealed that a core member of TeamPCP was utilizing an AI tool to develop a zero-day exploit for a widely used login software framework, specifically designed to bypass two-factor authentication (2FA). Google obtained a copy of the exploit code, tested and verified its efficacy, and promptly alerted the affected software vendor, allowing them to issue a security patch before the exploit could be weaponized at scale. This incident stands as one of the few documented instances of an in-the-wild, AI-generated vulnerability exploitation being intercepted and mitigated proactively.

Betrayals and the Unraveling of Operant Security

Despite their massive haul of stolen data, TeamPCP struggled to translate their access into substantial financial gains, reportedly pulling in only tens of thousands of dollars in extortion payments—far below the millions amassed by comparable ransomware and extortion syndicates. In an effort to monetize their database more effectively, TeamPCP brought in external cybercriminal partners, granting them access to the stolen credentials in exchange for a cut of future extortion payouts.

Among these partners was ShinyHunters, a notoriously prolific and long-standing cybercriminal collective known for high-profile data thefts and large-scale ransomware operations, including the breach of the Canvas educational platform that impacted thousands of schools across the United States.

The partnership, however, quickly soured. In April, ShinyHunters turned on their associates, utilizing TeamPCP’s stolen credentials to conduct independent extortion campaigns while withholding any financial cut from the supply-chain hackers. In a dramatic display of underworld betrayal, ShinyHunters went so far as to send Google’s Larsen a complete log of TeamPCP’s internal chat server—unaware that Larsen’s team already possessed direct access via their undercover mole.

The public taunting by ShinyHunters on social media platforms alerted TeamPCP leadership to internal security breaches. Reacting swiftly, the group purged several members from the CanisterWorm chat, exiled ShinyHunters, migrated their data to a new server, and tightened their inner circle.

Traditional Detective Work and the Downfall of Suspects

Even after Google’s undercover analyst was locked out of the core chat following the purge, traditional digital forensics and poor operational security (opsec) sealed the fate of the group’s leadership.

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Larsen traced the digital footprint of a primary user handle in the CanisterWorm chat back to a user data leak from the illicit hacker forum BreachForums, where the account was registered under the Gmail address [email protected]. Further archival searches revealed a historical dispute from 2019 involving the same pseudonym and a seller of pirated Microsoft Office keys, where the user requested a refund using a PayPal account linked to the email address [email protected].

Concurrently, when TeamPCP shifted its stolen credentials to a new hosting provider, intelligence gathered through trusted security partners indicated that the new server was being automatically backed up to a Google Drive account tied directly to the same [email protected] address. Finding illicit stolen data being funneled into a personal Google Drive account associated with a real-world identity provided the definitive link needed for law enforcement.

Google handed its intelligence package over to the Federal Bureau of Investigation (FBI), which moved quickly through legal channels to secure data warrants. This dossier, combined with parallel independent investigations by cybersecurity journalists and researchers such as Brian Krebs, established the identities of the primary suspects behind the operation.

Legal Actions and International Arrests

In late August, a joint law enforcement operation executed by the Australian Federal Police, with crucial assistance from the FBI and international partners, led to the arrest of two Australian men in their early twenties. Ruben Ian Thomson and Louis Michael Gaebler were taken into custody and formally charged with serious cybercrime offenses. Under strict Australian privacy laws, official police press releases did not initially name the suspects, but subsequent reporting and court filings identified Thomson and Gaebler as the principal orchestrators behind TeamPCP.

Footage released by Australian authorities showed Thomson being escorted out of a suburban home in Hamilton Hill, dressed casually in a hoodie and sweatpants, marking the physical conclusion of a digital manhunt that spanned multiple continents. While the FBI declined to comment on active investigations beyond highlighting their strategic partnership framework outlined in the official FBI Cyber Strategy, the arrests effectively dismantled the leadership tier of one of the most disruptive hacking collectives of the decade.

The Broader Implications for Cybersecurity

The TeamPCP saga represents a watershed moment for the cybersecurity industry, illustrating both the vulnerability of modern open-source supply chains and the evolving posture of private threat intelligence entities.

Throughout the operation, Google maintained strict ethical and operational boundaries. Larsen emphasized that the undercover analyst never engaged in illegal hacking, nor did they encourage or facilitate any of TeamPCP’s breaches, acting strictly as a passive observer with carefully maintained guardrails.

Crucially, the infiltration and subsequent disruption underscore a broader strategic pivot within organizations like Google’s Threat Intelligence Group and its newly established Cyber Disruption Unit. For years, the standard operating procedure for security researchers was diagnostic: identifying vulnerabilities, writing threat reports, and advising clients after an incident occurred. The TeamPCP case demonstrates a shift toward active intervention—disrupting command-and-control infrastructure, revoking stolen credentials at the source, and collaborating directly with law enforcement to neutralize criminal enterprises before they can fully realize their objectives.

As software supply chains grow increasingly complex and threat actors adopt automated, AI-augmented tooling, the traditional reactive security model is proving insufficient. The takedown of TeamPCP serves as both a cautionary tale about the fragility of open-source ecosystems and a blueprint for how proactive, intelligence-driven disruption can successfully dismantle sophisticated cybercrime syndicates from the inside out.

Leave a Reply

Your email address will not be published. Required fields are marked *