An undercover Google analyst infiltrated a notorious supply-chain hacking gang

by | Oct 7, 2026 | Technology

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Google’s threat intelligence division disclosed that it had embedded an undercover researcher within TeamPCP, a hacking collective responsible for one of the largest coordinated supply-chain attacks on record. The infiltration provided real-time visibility into the group’s operations during their peak activity, enabling Google to monitor their activities, alert targeted companies, and help prevent further exploitation.

TeamPCP emerged in late 2025 and conducted a series of cascading attacks against open-source software projects and technology companies. The group compromised software tools including Trivy, LiteLLM, and others, then leveraged those breaches to steal developer credentials and plant malware in additional widely-used applications. This chain-reaction approach allowed the hackers to breach over a thousand organizations, including GitHub, OpenAI, and the European Commission. The group also deployed an automated worm called Mini Shai-Hulud to expand its reach.

According to Google Threat Intelligence researcher Austin Larsen, Mandiant, Google’s security subsidiary, placed an undercover analyst within TeamPCP’s core group starting in March, gaining access to the approximately 12-member inner circle and their primary communication channel. This insider access provided crucial information about the group’s stolen credentials and attack plans. Rather than notify each victim individually, Google coordinated with major credential providers like Amazon Web Services and Microsoft to revoke stolen access tokens, preventing the hackers from exploiting them. Google also sent hundreds of notification emails to affected organizations.

In August, Australian police arrested two individuals in their early twenties identified as principal participants in TeamPCP. The arrests followed operational security mistakes made by one suspect, which Google identified and shared with law enforcement. Google also received intelligence from ShinyHunters, a rival cybercriminal group that had partnered with TeamPCP before turning against them. Additionally, the insider access revealed that TeamPCP members were developing a zero-day exploit targeting two-factor authentication systems in widely-used login software.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI