
Google’s threat intelligence division revealed that it had placed an undercover analyst inside TeamPCP, a hacking collective responsible for one of the largest supply-chain attacks on record. The infiltration provided real-time visibility into the group’s operations during their peak activity, enabling Google to gather intelligence and disrupt their malicious campaigns.
TeamPCP, which emerged in late 2025, orchestrated a sophisticated series of attacks targeting open-source software and developer infrastructure. The group compromised widely-used tools including the security scanner Trivy, the AI tool LiteLLM, and platforms associated with Checkmarx and TanStack. These initial breaches allowed the hackers to steal developer credentials and perpetuate additional attacks across a cascading network of targets. Over the course of their campaign, TeamPCP reportedly breached more than a thousand companies, including GitHub, OpenAI, and the European Commission. The group also deployed an automated worm called Mini Shai-Hulud to scale their hacking efforts.
According to Austin Larsen, a researcher from Google’s Threat Intelligence Group who presented findings at a security conference, Google’s undercover operative gained access to TeamPCP’s inner communication channels in March, just as the group’s campaign was intensifying. The analyst became one of approximately a dozen core members with access to the group’s primary chat platform. This position allowed Google’s team to locate a server storing thousands of stolen credentials that TeamPCP had obtained from victims and planned to use in extortion schemes.
Google’s response focused on rapidly disrupting the campaign rather than notifying individual victims directly. The company contacted major cloud service providers including Amazon Web Services and Microsoft to revoke the stolen credentials before attackers could exploit them. This approach proved more efficient than alerting each breached company individually. Additionally, Google’s access to TeamPCP’s communications revealed that members were developing a zero-day exploit targeting two-factor authentication systems.
Last month, two Australian nationals in their early twenties, identified as Ruben Ian Thomson and Louis Michael Gaebler, were arrested in a joint operation involving Australian police and the FBI. The arrests followed operational security mistakes made by the suspects and intelligence shared by ShinyHunters, a separate cybercriminal group that had partnered with TeamPCP before turning against them. Google provided law enforcement with key identifying information that contributed to the investigation.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI