Skip to content
← All news
3 min read

A Google analyst went undercover to infiltrate a supply chain hacking gang

A Google Threat Intelligence analyst spent months undercover inside TeamPCP, a gang linked to more than 1,000 breaches and a self-spreading worm, leading to two arrests in Australia.

Google's undercover analyst spent months inside a gang blamed for 1,000+ breaches. Two arrests followed.

Open-source package registries have no gatekeeper checking who a new maintainer really is, which is exactly the gap a hacking group calling itself TeamPCP spent years exploiting. Google's Threat Intelligence Group, working inside its Mandiant division, disclosed in mid-September that one of its analysts spent months undercover inside the group, using a fake persona to earn a place in its inner circle.

TeamPCP's own record, per Google, runs to more than 1,000 compromised organizations, hundreds of poisoned open-source packages, hijacked developer accounts, and a self-spreading worm the group nicknamed Mini Shai-Hulud. Google says the group exfiltrated more than 300 gigabytes of data and stole over 500,000 credentials over its lifetime.

Google's undercover persona was invited into TeamPCP's inner circle around March 2026, gaining access to a core chat called CanisterWorm with roughly a dozen members, close to the group's earliest activity. Separately, Google says it received intelligence from ShinyHunters, a rival criminal group that turned on TeamPCP, giving investigators a second line into the same network.

That visibility let Google warn victims and disrupt exploitation in real time, and the operational security mistakes TeamPCP made along the way went to law enforcement. Australian Federal Police, working with the FBI, arrested two alleged ringleaders: Ruben Ian Thomson, 21, facing eight charges, and Louis Michael Gaebler, 23, facing six. Austin Larsen of Google's Threat Intelligence Group disclosed the operation on the record at LABScon, an invite-only security conference in Scottsdale, Arizona, during the week of September 18. Wired first reported the story.

What is not yet public is how much of the 300 gigabytes Google has been able to attribute to specific victims, or whether TeamPCP's poisoned packages are still live anywhere in dependency trees that have not been audited since.

Why a build studio cares

Supply chain compromise is the risk our Deep and Full Audits are built to find: a poisoned dependency, a hijacked maintainer account, a package that behaved correctly for years before it did not. TeamPCP's worm, Baseten's three-year-old leaked GitHub token found by an automated pentest agent in 25 minutes, and the swarm of agents that hit RubyGems this month are the same failure domain wearing three different faces: a secret or a package sat exposed somewhere nobody was still checking, until something automated finally looked.

Next step: read Ars Technica's report on the operation, sourced to Wired's original story. If your own dependency tree has not had a fresh look since the last time something broke, write to us at hello@gattyworks.com.

Supply Chain SecurityGoogleOpen SourceThreat IntelligenceTeamPCPGoogleMandiantSupplyChainSecurityOpenSourceShinyHuntersCyberSecurityThreatIntelligenceInfoSecSoftwareSecurity

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.
Book a call