An undercover Google analyst infiltrated a notorious supply chain hacking gang during its unprecedented global digital rampage.

Before two of its primary architects were apprehended in Australia last month, the cybercriminal entity operating under the moniker TeamPCP orchestrated a sophisticated and chaotic campaign that shattered industry standards for software supply-chain security. By systematically tainting hundreds of open-source repositories and hijacking developer accounts, the group managed to compromise over a thousand corporate entities. While the scale of these attacks was unprecedented, the most significant revelation to emerge from the aftermath is that Google’s threat intelligence apparatus had a clandestine operative embedded within the group’s inner circle for nearly the entirety of its active operation.
The details of this infiltration, recently disclosed by Google Threat Intelligence Group researcher Austin Larsen at the SentinelOne LABScon conference, provide a rare glimpse into the high-stakes world of proactive digital defense. Through a combination of strategic undercover work, technical analysis, and inter-organizational cooperation, Google was able to monitor, disrupt, and eventually assist law enforcement in dismantling the syndicate.
A Timeline of the TeamPCP Rampage
The emergence of TeamPCP in late 2025 marked a paradigm shift in how threat actors weaponize open-source ecosystems. The group’s methodology relied on a recursive cycle of compromise: by breaching one software project, they gained the credentials necessary to infiltrate the next, creating a cascading effect of supply-chain contamination.
The operational timeline began in earnest during the spring of 2026. According to Google’s intelligence, the group successfully targeted a series of critical development tools and platforms, including the Trivy security scanner, the LiteLLM API tool, the infrastructure of security firm Checkmarx, the TanStack library, and the Mistral AI enterprise platform. These intrusions acted as bridgeheads, allowing the attackers to pivot into more sensitive environments, including the GitHub repository, the data contracting firm Mercor, and the internal systems of high-profile organizations such as OpenAI and the European Commission.
Central to their scaling strategy was the deployment of a self-spreading, automated worm dubbed "Mini Shai-Hulud." Drawing inspiration from the science fiction epic Dune, the worm was designed to automate the credential-harvesting process, allowing the group to expand its reach far beyond what manual exploitation would permit.
The Role of the Mandiant Mole
The most striking aspect of the investigation is the role played by an undercover analyst from Mandiant, a Google-owned cybersecurity subsidiary. According to Larsen, the analyst had been working for months to cultivate a persona capable of gaining the trust of the group’s core members. Their patience paid off in March 2026, when the operative was invited to join "CanisterWorm," a restricted, 12-member chat group that served as the nerve center for TeamPCP’s operations.

"Essentially, almost day one, Mandiant was watching everything behind the scenes," Larsen stated. This access provided a real-time window into the group’s decision-making, technical methodology, and the massive repository of stolen credentials they were accumulating.
The intelligence gathered from within the group was immediately operationalized. Rather than engaging in the time-consuming process of notifying every individual victim, Google opted for systemic disruption. The security team proactively contacted major service providers, including Amazon Web Services and Microsoft, to revoke stolen credentials before they could be leveraged for extortion. By working with the infrastructure providers that hosted the stolen data, Google effectively neutralized the group’s primary weapon—the "keys to the kingdom"—before the hackers could capitalize on their haul.
The Anatomy of an AI-Driven Zero-Day
Beyond mere supply-chain interference, the infiltration revealed a concerning trend: the integration of artificial intelligence into the offensive hacking lifecycle. The undercover source discovered that TeamPCP members were using AI tools to develop a zero-day exploit targeting a widely used authentication system.
The objective was to bypass two-factor authentication (2FA) mechanisms, a staple of modern cybersecurity. Google’s team obtained a copy of the exploit code, verified its efficacy in a controlled environment, and alerted the affected software developer. The subsequent patch effectively closed the vulnerability, preventing what could have been a catastrophic widespread breach. This incident serves as a significant case study in the evolving threat landscape where generative AI is increasingly utilized by malicious actors to accelerate the discovery and exploitation of software flaws.
Internal Betrayal and Operational Security Failures
The downfall of TeamPCP was accelerated not only by external pressure but by internal decay and professional rivalry. Despite their massive acquisition of over half a million user credentials, the group struggled to monetize the data efficiently. In an attempt to increase their revenue, they entered a partnership with the infamous hacking group ShinyHunters.
This decision proved to be a fatal strategic error. In April 2026, ShinyHunters effectively turned on their partners, performing their own unauthorized extractions using the credentials provided by TeamPCP and sharing internal logs with external researchers, including Google’s team. This "honor among thieves" failure created additional friction, causing TeamPCP to exile members and move servers, which ultimately led to the operational security (OpSec) blunders that sealed their fate.
The final trail of breadcrumbs involved the use of a personal Gmail account—[email protected]—linked to a series of forum disputes and, eventually, a Google Drive account used to store stolen material. The audacity of linking illicit data to a personal account tied to one’s true identity provided the definitive evidence needed for federal intervention.

Law Enforcement and Global Impact
The investigation culminated in the arrest of two Australian nationals, identified as Ruben Ian Thomson and Louis Michael Gaebler, in late August 2026. The arrests were the result of a collaborative effort involving the Australian Federal Police (AFP) and the FBI.
While the FBI declined to comment on specific details regarding the case, the agency emphasized its commitment to the "Cyber Strategy" released earlier in 2026, which highlights the importance of private-public partnerships in disrupting adversary networks. The arrest of the two men, who were reported to be in their early twenties, underscores the reality that sophisticated, high-impact cybercrime is no longer the exclusive domain of state-sponsored actors, but can be carried out by small, highly skilled, and sometimes reckless groups of individuals.
The Broader Implications for Cybersecurity
The infiltration of TeamPCP represents a significant shift in the operational philosophy of major technology firms like Google. Historically, security firms focused on reactive defense—releasing patches and writing reports after a breach had occurred. However, the formation of Google’s Cyber Disruption Unit marks a transition toward a more aggressive, preventative stance.
"Writing reports can only be so useful. Taking action to protect users and customers—that is the next step," Larsen explained.
The implications for the broader tech ecosystem are profound. The TeamPCP incident highlights the extreme vulnerability of the software supply chain, where a single compromised open-source library can lead to a systemic failure affecting government agencies and major corporations alike. As the industry moves forward, the success of the Google infiltration suggests that deeper, more integrated intelligence-gathering will be necessary to combat the next generation of threat actors.
However, the "fly on the wall" nature of the operation also raises questions about the ethical and legal boundaries of corporate surveillance. While the participants in the investigation maintained that their operative never encouraged illegal activity, the ability of a private entity to infiltrate a criminal group and coordinate with federal law enforcement sets a high-stakes precedent. As artificial intelligence continues to lower the barrier to entry for complex hacking, the tension between reactive security and proactive, potentially invasive, disruption will likely define the future of global cybersecurity.







