Google Threat Intelligence Insider Infiltrated Notorious TeamPCP Software Supply Chain Hacking Ring Months Before Arrests

The landscape of modern cybersecurity changed irrevocably last month when law enforcement agencies in Australia, supported by international bodies such as the FBI, apprehended two primary suspects alleged to be the masterminds behind TeamPCP. This notorious hacker collective had executed a software supply-chain attack spree that was arguably unprecedented in scale and audacity. Before their arrests, TeamPCP had managed to compromise hundreds of open-source programs, hijack critical developer accounts, and deploy a self-spreading, Dune-themed worm across the global digital ecosystem, ultimately breaching well over a thousand corporate and governmental entities.
However, the full narrative behind the takedown of TeamPCP involves a remarkable piece of cyber espionage. Google’s Threat Intelligence Group revealed that an undercover analyst from Mandiant, Google’s premier security subsidiary, had successfully infiltrated the inner circle of TeamPCP almost from the inception of its public rampage. Operating as a quiet observer, this undercover asset provided Google with unprecedented visibility into the hackers’ operations. This inside access enabled the security giant to monitor malicious activities in real time, issue critical warnings to targeted organizations, and actively disrupt the threat actors’ attempts to weaponize stolen credentials.
The details of this operation were brought to light by Google Threat Intelligence Group researcher Austin Larsen during a presentation at the LABScon research conference, hosted by cybersecurity firm SentinelOne. The disclosures shed light on how private-sector intelligence gathering, internal operational security (opsec) failures, and inter-criminal betrayals converged to dismantle one of the most destructive supply-chain hacking campaigns in recent memory.
Anatomy of an Unprecedented Supply-Chain Campaign
TeamPCP emerged into the public consciousness in late 2025, rapidly establishing a reputation for sophisticated and cascading attacks against the global software supply chain. Rather than targeting organizations through conventional perimeter breaches, the group focused on poisoning open-source repositories and packages. By inserting malicious payloads into trusted software development tools, TeamPCP could automatically compromise the systems of downstream developers, cascading infections to thousands of organizations worldwide.
Starting in the spring, the hacking spree intensified. TeamPCP systematically targeted several high-profile open-source utilities and platforms, including the Trivy security scanner, the LiteLLM application programming interface tool, infrastructure belonging to web application security firm Checkmarx, the TanStack web application library, and enterprise AI platform Mistral AI. Each successful compromise expanded the group’s reach, yielding administrative access to major repositories like GitHub, data contracting firm Mercor, and sensitive internal environments at OpenAI and the European Commission.
To automate and scale this campaign, the hackers occasionally deployed a specialized worm dubbed "Mini Shai-Hulud," named after the iconic giant sandworms of Frank Herbert’s science fiction epic Dune. The moniker also nodded to an earlier, separate intrusion campaign from September 2025 involving a similarly themed worm, though investigators are still untangling whether TeamPCP members participated in those earlier incursions.
The Undercover Mole Inside CanisterWorm
The clandestine operation by Google’s security division began months before the arrests of Ruben Ian Thomson and Louis Michael Gaebler in late August. According to Larsen, an undercover persona meticulously cultivated by Mandiant spent months establishing trust with a cybercriminal actor who was ultimately invited to join TeamPCP’s inner circle.
By March, just as TeamPCP was ramping up its supply-chain attacks, this undercover analyst was granted access to the group’s core administrative chat channel, designated "CanisterWorm." Restricted to approximately 12 trusted members, the channel served as the central command-and-control hub where the hackers coordinated intrusions, shared stolen data, and boasted about their exploits. In leaked chat logs presented by security researchers, one TeamPCP member overtly celebrated their dominance, writing, “You guys should understand that we pulled off the biggest supply chain maybe ever recorded in modern history.”

For Michael Fletcher, a former Australian Federal Police (AFP) analyst now working in private threat research, the depth of Google’s early penetration became apparent when he contacted Larsen regarding monitoring strategies for the group. Larsen advised Fletcher to exercise caution during his investigations because one of the primary threat actors was essentially a friendly asset. Reflecting on the exchange, Fletcher noted the sheer impact of having institutional eyes inside the criminal group from such an early stage.
Disruption Operations and Thwarting AI Exploits
With a front-row seat to TeamPCP’s operations, Google’s undercover analyst gained visibility into a centralized server where the group stored troves of stolen credentials—including usernames, passwords, and access tokens harvested from hundreds of victim organizations. Recognizing the imminent danger of large-scale extortion schemes, Larsen and his team prioritized immediate disruption over passive observation.
Directly notifying every affected company individually would have proven too slow to prevent exploitation given the sheer volume of breaches. Instead, Google adopted a triage strategy: the company reached out directly to major cloud and infrastructure providers—such as Amazon Web Services and Microsoft—where the stolen credentials were valid. By alerting these service providers, Google facilitated the rapid revocation of compromised tokens and access keys, neutralizing TeamPCP’s ability to access victim environments. Hundreds of notification emails were dispatched to platforms and subsequent victims, mitigating potential damages significantly.
Beyond intercepting credential abuse, Google’s inside visibility exposed a more advanced technical threat. Monitoring the CanisterWorm chat revealed that a core member of TeamPCP was leveraging artificial intelligence to develop a zero-day exploit targeting a widely used authentication software. The exploit was designed to completely bypass two-factor authentication (2FA) mechanisms.
Google’s engineering team acquired a copy of the AI-generated exploit code, tested its validity, and confirmed its efficacy with minor modifications. This marked a rare and alarming confirmation of threat actors successfully utilizing generative AI to weaponize unknown software vulnerabilities in the wild. Google immediately alerted the affected software vendor, enabling them to patch the security flaw before widespread exploitation could occur—an incident initially detailed in a Google threat intelligence case study published in May without naming the specific threat group.
Betrayal Within the Ranks and Slipping Opsec
Despite their technical sophistication, TeamPCP faced monetization challenges that ultimately fractured the group. According to AFP estimates, the hackers had accumulated credentials for more than half a million users. However, their yields from extortion attempts were relatively modest, bringing in tens of thousands of dollars rather than the millions typically reaped by established ransomware syndicates.
Seeking to maximize profits, TeamPCP invited external cybercriminal organizations to partner with them, granting these groups access to their stolen data repository in exchange for a percentage of any successful extortion payments. Among their partners was ShinyHunters, a prolific and notorious hacking collective historically responsible for massive corporate data thefts and high-profile ransomware incidents, such as the Canvas educational software platform breach that disrupted thousands of schools across the United States.
The partnership proved disastrous for TeamPCP. By April, just weeks after joining forces, ShinyHunters went rogue. The partner group began executing its own independent extortion operations using TeamPCP’s stolen credentials while withholding any financial cut from the supply-chain hackers. In a brazen display of betrayal, ShinyHunters forwarded a complete log of TeamPCP’s internal server chats to Larsen’s team unsolicited, unaware that Google already maintained an active mole within the group.
ShinyHunters also publicly taunted TeamPCP on social media platform X. The loud betrayal forced TeamPCP into panic mode. Leadership ordered members to delete shared files, severed ties with ShinyHunters, migrated their stolen data repository to a new server, and purged several members from the CanisterWorm chat, inadvertently cutting off Google’s undercover analyst in the process.

Traditional Detective Work and Law Enforcement Action
Even after losing their direct line into the CanisterWorm chat, security researchers relied on traditional digital forensics and operational security lapses to finish tracking down the perpetrators.
Austin Larsen traced the digital footprint of a hyper-active chat participant using public breach data. Examining a leaked database from the now-defunct cybercriminal forum BreachForums, Larsen connected a primary TeamPCP handle to the Gmail address [email protected]. Digging deeper into historical forum archives, he uncovered a 2019 commercial dispute where the user "sheepstealing" demanded a refund from a vendor of pirated Microsoft Office keys, directing the seller to a PayPal account associated with [email protected].
Concurrently, when TeamPCP migrated its stolen data to a new server hosted by an alternative provider, Google learned through a trusted industry partner that the threat actors were actively backing up their illicit trove to a Google Drive account tied directly to that same [email protected] address. Astonished by the glaring security oversight, Larsen immediately escalated the intelligence to the FBI. Within minutes, federal law enforcement officers responded to the tip.
Following standard international legal procedures, the FBI secured data warrants for the Google account. This evidence culminated in late August when Australian Federal Police, operating in coordination with the FBI, executed raids and arrested two men in their early twenties: Ruben Ian Thomson and Louis Michael Gaebler. Video footage released by law enforcement showed Thomson being escorted out of a suburban home in Western Australia. Both individuals have been formally charged with serious computer intrusion and hacking offenses.
The Broader Implications for Cyber Defense
The takedown of TeamPCP marks a significant philosophical shift in how private threat intelligence organizations operate. Historically, companies like Google’s Mandiant operated primarily in a defensive posture—observing threats, cataloging attacker methodologies, and publishing retrospective threat reports.
However, the launch of specialized initiatives, such as Google’s Cyber Disruption Unit, signals a aggressive departure from traditional boundaries. Security researchers are increasingly adopting proactive stances to disrupt criminal operations before catastrophic harm occurs, walking a fine legal and ethical line.
Larsen emphasized that Google’s undercover analyst strictly adhered to legal and ethical guardrails throughout the operation. The operative never engaged in malicious hacking, nor did they encourage or facilitate TeamPCP’s intrusions. Instead, the persona functioned purely as an observer, maintaining cover just enough to avoid suspicion while funneling life-saving intelligence to defenders.
As global cybercrime syndicates increasingly leverage automated tools, artificial intelligence, and software supply-chain vectors, the TeamPCP case serves as both a cautionary tale regarding operational security failures among threat actors and a blueprint for effective public-private collaboration in modern cybersecurity enforcement. While threat reports remain valuable, the active disruption of cybercriminal operations may well define the next era of digital defense.







