An undercover Google analyst infiltrated a notorious supply-chain hacking gang

by | Oct 11, 2026 | Technology

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Google’s threat intelligence division revealed that it had successfully infiltrated TeamPCP, a hacking group responsible for an extensive supply-chain attack campaign affecting hundreds of organizations. The company disclosed this undercover operation during a presentation at a security conference, detailing how its embedded researcher monitored the group’s activities from within their inner circle and helped disrupt their operations.

TeamPCP emerged in late 2025 and conducted a series of cascading supply-chain attacks that compromised numerous open-source software projects and developer credentials. The group targeted tools including Trivy, LiteLLM, and infrastructure belonging to Checkmarx, ultimately breaching major organizations including GitHub, OpenAI, and the European Commission. The hackers employed a self-spreading worm called Mini Shai-Hulud to automate their attacks and expand their reach to additional victims.

Google’s undercover analyst was added to the group’s core communications channel in March, gaining access to stolen credentials and internal discussions. Using this visibility, Google’s security team moved quickly to disrupt TeamPCP’s extortion scheme by coordinating with major cloud providers and software platforms to revoke compromised credentials before the attackers could exploit them. The company also passed operational security details it gathered to law enforcement authorities.

Last month, Australian police arrested two individuals in their early 20s identified as principal participants in TeamPCP, with assistance from the FBI. Google’s investigation also incorporated intelligence from ShinyHunters, a rival cybercriminal group that had partnered with but later turned against TeamPCP. According to researchers, Google’s proactive approach to alerting providers and victims helped prevent additional compromises during the group’s active hacking campaign.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI