An undercover Google analyst infiltrated a notorious supply-chain hacking gang

by | Sep 27, 2026 | Technology

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Google’s Threat Intelligence Group disclosed that it had successfully embedded an undercover analyst within TeamPCP, a hacking collective responsible for one of the most extensive supply-chain attack campaigns on record. The group conducted a coordinated series of intrusions targeting open-source software projects, stealing developer credentials, and deploying malware across hundreds of programs to gain access to thousands of organizations. Two individuals identified as Ruben Ian Thomson and Louis Michael Gaebler, both Australian nationals in their early twenties, were arrested last month following a joint investigation involving Australian police and the FBI and charged in connection with the hacking crimes.

TeamPCP emerged online in late 2025 and gained notoriety for its sophisticated approach to supply-chain compromises. Beginning in the spring, the group targeted multiple high-profile projects including the security scanner Trivy, the AI tool LiteLLM, and infrastructure belonging to Checkmarx. Through this cascading methodology, each successful breach provided access to developer accounts that enabled further intrusions into additional software repositories and systems. The group’s victims included GitHub, OpenAI, the European Commission, and numerous other organizations. At certain points, TeamPCP deployed an automated worm dubbed Mini Shai-Hulud, named after creatures from the science fiction novel Dune, to scale its operations.

According to Austin Larsen, a researcher with Google’s Threat Intelligence Group, Mandiant, Google’s security subsidiary, had positioned an undercover analyst within the group’s inner circle beginning in March as the attacks intensified. This embedded source provided access to internal communications and a server containing credentials stolen from compromised organizations. Google leveraged this intelligence to quickly notify credential providers including Amazon Web Services and Microsoft, enabling them to revoke access before the hackers could exploit the stolen authentication data. The intelligence also revealed that members within the group’s core circle were developing a zero-day exploit targeting login software to circumvent two-factor authentication systems. Larsen emphasized that the primary objective was to disrupt the campaign as rapidly as possible to prevent additional compromises.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI