
Google’s threat intelligence group disclosed that it maintained an undercover researcher embedded within the leadership of TeamPCP, a hacking collective responsible for one of the largest supply-chain compromise campaigns on record. The infiltration provided real-time visibility into the group’s operations during a period when the hackers were conducting coordinated attacks against hundreds of software projects and thousands of companies.
Two individuals from Australia were arrested and charged with hacking offenses last month in connection with their alleged roles as principal participants in TeamPCP. The group, which emerged online in late 2025, conducted a series of cascading attacks targeting open-source software repositories and developer infrastructure. The hackers would compromise security tools and widely used libraries, then use stolen developer credentials to inject malicious code into additional software projects, creating a repeating cycle of breaches. Notable compromised projects included Trivy, LiteLLM, and infrastructure belonging to multiple technology companies. The group’s activities ultimately resulted in breaches affecting organizations including GitHub, OpenAI, the European Commission, and numerous others. TeamPCP deployed an automated worm called Mini Shai-Hulud to scale up its attack operations.
According to Google threat intelligence researcher Austin Larsen, a Mandiant analyst gained access to the group’s inner circle in March and participated in their core communications channel. This positioning allowed Google to access servers containing stolen credentials that TeamPCP intended to use for extortion schemes. Rather than notify individual victim companies directly, Google coordinated with major cloud and software providers including Amazon Web Services and Microsoft to revoke the compromised credentials, preventing the hackers from exploiting them. The company subsequently notified affected organizations of the breaches.
Larsen indicated that Google’s access to TeamPCP’s internal communications also revealed the group was developing a zero-day exploit targeting authentication software to bypass two-factor authentication mechanisms. The investigation benefited from intelligence shared by ShinyHunters, another criminal group that had partnered with TeamPCP before turning against them, and from operational security mistakes made by the arrested individuals that were shared with law enforcement.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI