[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fP85JCeAzzJa0TjO1gO1IaUVRJpxG95-0w4KAe5grvAM":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"a198d59f-a0ee-49a1-bc56-764154553fee","An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang","an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang-d64f69","TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.","Google's threat intelligence group revealed an undercover analyst infiltrated the notorious TeamPCP hacking gang. This mole provided inside access, allowing Google to monitor the group's extensive supply-chain attacks, warn targets, and assist in disrupting their operations. The investigation, which also leveraged intelligence from ShinyHunters, led to the identification of key suspects, two of whom were recently arrested in Australia.","Google analyst infiltrated TeamPCP, a notorious supply-chain hacking gang, aiding disruption and arrests.","CommentLoaderSave StorySave this storyCommentLoaderSave StorySave this storyBefore two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate that software supply-chain hacking, and even released a Dune-themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies.Now Google’s threat intelligence group has revealed that during a key moment of TeamPCP’s rampage, the company’s own undercover researcher had infiltrated the group—allowing Google to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group’s attempts to exploit those victims.In a talk at security firm SentinelOne's LABScon research conference today, Google Threat Intelligence Group researcher Austin Larsen will present details on the company’s investigation—and infiltration—of TeamPCP amidst the group’s unprecedented, chaotic supply-chain hacking campaign. According to Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hacker group and passed on key identifying details to law enforcement. The company also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with, but which later turned on the supply-chain hackers. And perhaps most surprisingly, Larsen says that Google’s security subsidiary Mandiant had an undercover analyst—not himself—within the group’s inner circle from almost the beginning of TeamPCP’s time in the spotlight.“One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group,” Larsen told WIRED in an interview ahead of his LABScon talk. “So essentially, almost day one, Mandiant was watching everything behind the scenes.”The TeamPCP MoleLate last month, Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early twenties, were arrested by Australian police in a joint investigation with assistance from the FBI, charged with hacking crimes, and described by the Australian Federal Police (AFP)—in a press release that, due to Australian privacy laws, did not name them—as “principal participants” in TeamPCP. The hacker group, which seems to have first appeared online in late 2025, had made headlines with a brazen string of cascading supply-chain attacks: It repeatedly compromised open-source software to hide its malware, which then allowed it to hijack the credentials of software developers and plant its malicious code in yet another widely used tool, in a repeating cycle.Starting this spring, for instance, TeamPCP compromised the open-source security scanner Trivy, the AI application programming interface tool LiteLLM, infrastructure of the web application security firm Checkmarx, the web app library TanStack, and the enterprise AI platform Mistral AI. Those repeated supply-chain attacks, with each enabling the group to cast its net again for more victims, ultimately allowed the hackers to breach open-source code repository Github, data contracting firm Mercor, and employee devices at OpenAI, the European Commission, and many others who have remained unnamed in public reporting. At times, the group deployed a worm known as Mini Shai-Hulud, named after the sandworms in Dune, to automate its hacking and scale up to even more victims. (The name also seemed to refer to an earlier Shai-Hulud worm that hackers designed to try a similar approach in September 2025, though it’s still not clear if TeamPCP or any of its alleged members were involved in that earlier intrusion campaign.)Larsen now says that in March, just as TeamPCP was beginning its frenzied supply-chain hacking, Google’s own undercover analyst was invited to join the hackers’ inner circle. That inside source, whose name Larsen declined to reveal, was one of about 12 members of the group given access to a core chat that TeamPCP called CanisterWorm.“You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history,” one TeamPCP member wrote in the leaked chats.Michael Fletcher, a former AFP analyst who now works in the threat research division of Australian telecom firm Telstra, says he approached Larsen around that time about methods for monitoring the group’s members and activities. He says that Larsen responded by asking Fletcher to approach the hackers with caution because one of them was a “friendly,” Fletcher remembers. “I thought, damn, you all have been inside this early,” he says.Google’s undercover analyst, Larsen says, gained access to a server where TeamPCP was storing its trove of credentials stolen from its many victims: the usernames, passwords, and access tokens it had obtained through its hacking and seemingly planned to use to extort target companies. So Google’s team decided to take action to warn victims and prevent TeamPCP’s ransom scheme. “My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen?” Larsen says. “Let's go mess up what they're doing. That was my goal.”Rather than focus on alerting the owners of the stolen credentials at victim companies directly, which Larsen says would have taken too long given the sheer number of breached companies, Google first reached out to providers where those credentials could be used, like Amazon Web Services and Microsoft, to have the credentials revoked and prevent the hackers from exploiting them. Larsen and his team sent out hundreds of notification emails to those providers and then to victims, many of which got immediate responses.Around the same time, Larsen says, Google’s visibility into the TeamPCP internal chat also allowed it to learn that someone within the group’s core circle was, distinct from the group’s supply-chain hacking, using an AI tool to develop a zero-day exploit in a widely used piece of login software that would allow the hackers to bypass its two-factor authentication. Google’s team got a copy of the exploit code, tested it out, and found that, with a few tweaks, it worked—a rare instance of an in-the-wild AI-created hacking technique that took advantage of a previously unknown software vulnerability. Google warned the software’s developer, who was able to patch its security flaw. (The incident was described in a case study Google released in May, but without naming TeamPCP or detailing how Google learned about the exploit.)More Betrayals, Sloppy OpsecGoogle’s analyst was not, it turns out, the only traitor in TeamPCP’s midst.Even prior to Google’s disruption effort, Larsen says, the group struggled to profit from its enormous collection of stolen data, which, according to the AFP, included more than half a million users’ credentials. Larsen estimates that, despite that haul, it was pulling in only tens of thousands of dollars in extortion payments, not the millions similar groups have amassed. So in an attempt to better monetize its hacking, TeamPCP invited multiple other cybercriminal groups to partner with it, giving them access to the stolen credentials in exchange for a percentage of any extortion payments they were able to extract.One of those cybercriminal partners was ShinyHunters, a years-old, highly prolific hacker group that has extorted millions of dollars from victims through data theft and ransomware, including in the breach of educational software platform Canvas that would later paralyze thousands of schools across the US. Around April, a few weeks after partnering with TeamPCP, ShinyHunters went rogue, Larsen says, carrying out its own extortions with TeamPCP’s credentials but without giving the supply-chain hackers their cut. ShinyHunters went so far as to share with ","https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fan-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang\u002F","https:\u002F\u002Fmedia.wired.com\u002Fphotos\u002F6aac35420820a9282b5f1721\u002Fmaster\u002Fpass\u002FSecurity_An%20Undercover%20Google%20Researcher%20Infiltrated%20the%20Gang%20Behind%20the%20Worst-Ever%20Supply%20Chain%20Hacking%20Spree_v1.jpg","2026-09-18T16:00:00+00:00","2026-09-18T18:00:15.821322+00:00",9,[18,21,23,26,28,31],{"name":19,"type":20},"TeamPCP","threat_actor",{"name":22,"type":20},"ShinyHunters",{"name":24,"type":25},"Google","vendor",{"name":27,"type":25},"Mandiant",{"name":29,"type":30},"Trivy","product",{"name":32,"type":30},"LiteLLM","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":33,"icon":35,"name":36,"slug":37},null,"Supply Chain","supply-chain",[39,41,46,51],{"category":40},{"id":33,"icon":35,"name":36,"slug":37},{"category":42},{"id":43,"icon":35,"name":44,"slug":45},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57],{"type":58,"value":59,"context":60},"malware","Mini Shai-Hulud","Self-spreading worm used by TeamPCP to automate attacks."]