Google Infiltrated TeamPCP to Expose Its Supply Chain Hacking Campaign
TeamPCP carried out an unprecedented series of software supply chain attacks before alleged members were arrested and charged in Australia last month. The hacker group contaminated hundreds of open source programs with malware, stole developer accounts to extend its attacks, and deployed self-spreading worms that automated the process and eventually infected more than 1,000 companies.
Google’s Threat Intelligence Group has revealed that one of its undercover researchers infiltrated TeamPCP at a critical point in the group’s rise. The operation allowed Google to monitor the hackers from inside, warn compromised targets, and thwart some of TeamPCP’s attempts to exploit victims.
Speaking at the LABScon security research conference, Google Threat Intelligence Group researcher Austin Larsen is expected to share details about the investigation and Google’s intrusion into TeamPCP’s chaotic supply chain hacking campaign. Larsen said Google followed a trail of operational security mistakes allegedly made by one of the two Australians accused of being a key TeamPCP member and passed identifying details to law enforcement.
Google also received information from ShinyHunters, another notorious cybercriminal group that was affiliated with TeamPCP before later attacking supply chain hackers. Most surprisingly, Larsen said, Google’s security subsidiary Mandiant had an undercover analyst inside TeamPCP’s circle from the time the group began attracting widespread attention.
“One of our personas was added to the group because we had been working for months to build a rapport with one of the actors who was invited to join TeamPCP,” Larsen told WIRED in an interview ahead of his LABScon talk. “Basically from almost day one, Mandiant was behind the scenes overseeing everything.”
How TeamPCP Built Its Supply Chain Attacks
Late last month, Reuben Ian Thomson and Louis Michael Gabler, both Australians in their early 20s, were arrested by Australian police in a joint investigation assisted by the FBI. They were charged with hacking offenses and described by the Australian Federal Police as “key participants” in TeamPCP. The AFP declined to name the group in its press release because of Australian privacy laws.
TeamPCP appears to have first emerged online in late 2025, drawing attention with a series of cascading supply chain attacks. The hackers repeatedly compromised open source software to conceal malware, hijacked software developer credentials, and embedded malicious code into additional widely used tools. This enabled them to repeat the attack cycle and reach more victims.
Since this spring, TeamPCP has compromised the open source security scanner Trivy, the LiteLLM artificial intelligence application programming interface tool, the infrastructure of web application security company Checkmarx, the TanStack web application library, and enterprise AI platform Mistral AI.
The repeated supply chain attacks helped the group target additional victims, including the open source code repository GitHub, data contracting company Mercor, OpenAI employee devices, the European Commission, and others not identified in public reports.
At various points, TeamPCP deployed self-spreading worms known as mini-shy fluids. These worms automated the attacks and helped spread them to more victims. The name appears to reference an earlier Shai-Hulud worm that hackers used in an attempted similar campaign in September 2025. It is not yet clear whether TeamPCP or its alleged members were involved in that initial intrusion campaign.
Google Researchers Entered TeamPCP’s Inner Circle
Larsen said Google’s undercover analysts were invited to join the hackers’ inner circle in March, when TeamPCP began its supply chain hacking spree. The undercover source, whose identity Larsen declined to disclose, was one of roughly a dozen members of a group called CanisterWorm that had access to TeamPCP’s core chat.
Source: www.wired.com


