An undercover Google analyst infiltrated a notorious supply-chain hacking gang

by | Sep 23, 2026 | Technology

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Google’s threat intelligence division disclosed that it had embedded an undercover researcher within the inner circle of TeamPCP, a hacking group responsible for one of the most extensive software supply-chain compromises on record. The infiltration occurred in March, just as TeamPCP began its coordinated series of attacks targeting widely used open-source software projects and commercial platforms.

TeamPCP conducted a sophisticated campaign involving the compromise of numerous open-source tools including Trivy, LiteLLM, and TanStack, which the group then leveraged to steal developer credentials and inject malware into additional software projects. This cascading attack pattern allowed the hackers to breach major targets including GitHub, OpenAI, and the European Commission. The group also deployed an automated worm named Mini Shai-Hulud to expand the scope of their operations. Last month, Australian police arrested two individuals identified as principal participants in the group’s activities, with assistance from the FBI.

Google’s undercover analyst, working through the company’s security subsidiary Mandiant, gained access to the group’s internal communications and servers storing stolen credentials from compromised organizations. Rather than immediately notifying individual victim companies—a process Larsen said would have been too time-consuming given the scale of breaches—Google first contacted major cloud service providers like Amazon Web Services and Microsoft to revoke the stolen credentials and prevent their exploitation.

Google Threat Intelligence Group researcher Austin Larsen detailed the investigation and infiltration operation at a security conference, explaining how the company’s insider access enabled rapid disruption of TeamPCP’s extortion schemes. The research also revealed that other cybercriminal groups, including ShinyHunters, provided intelligence on TeamPCP to authorities. Additionally, Google’s monitoring of internal group communications uncovered plans by members to develop zero-day exploits targeting authentication software.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI