TRENDING
Five alphabetical thumb-index tabs cut into the edge of a dictionary, each labeled with a letter range
September 27, 2026
How to Build a Trie From Scratch in Python for Fast Prefix Search and Autocomplete
Five sample state-issued EBT benefit cards fanned out on a white background
September 27, 2026
AI-Made Fake Cards Turn an Old Mail Scam Into a Growing Fraud Wave
A real wooden outdoor sandbox filled with sand and toys, empty of people
September 27, 2026
OpenAI Pauses Training of Its Most Capable Models for the Second Time in Three Months
Subway turnstiles showing a green ENTER sign and a red DO NOT ENTER sign side by side
September 27, 2026
How to Verify Cloudflare Turnstile Tokens Server-Side in a Python App
Macro photo of a brass keyhole with a key partially inserted in a wooden door
September 27, 2026
TU Graz’s File Notification Attacks Turn a Decades-Old OS Feature Into a Side Channel
27 Sep 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
A green highway sign splitting into an EXPRESS lane and a LOCAL lane, the same express-lane idea a skip list uses to skip ahead through sorted data
How to Build a Skip List in Python to Get Balanced-Tree Speed Without the Rotations
September 27, 2026
Two well-worn paper archery targets riddled with arrow holes, mounted on cardboard backing at an outdoor range
Red Hat’s RHEL 10 STIG Update Turns Compliance Into a Moving Target
September 27, 2026
A manila file folder with a paperclip clipped to its tab, against a white background
CISA Orders Federal Agencies to Patch a SharePoint RCE Flaw Microsoft First Called Spoofing
September 27, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 210 Posts
News 211 Posts
Learning Hub 181 Posts
Home/Articles/Google’s TeamPCP Mole Turns Threat Intelligence Into a Spy Operation
Articles

Google’s TeamPCP Mole Turns Threat Intelligence Into a Spy Operation

Google's threat intelligence group says an undercover analyst spent months inside a supply-chain hacking gang's private channel, helping identify two Australian suspects now facing criminal charges.

September 20, 2026 6 Min Read
20

Before Australian police arrested two men in the Perth suburbs of Cottesloe and Mandurah on August 26, 2026, the hacking group known as TeamPCP had spent months tearing through the open-source software supply chain, using each compromised tool to steal the credentials needed to compromise the next one. What victims and outside researchers did not know until this week is that Google had someone on the inside almost the entire time.

Table Of Content

  • What TeamPCP Actually Did
  • Building Trust From Nearly Day One
  • A Criminal Partner Turns Informant
  • From Chat Logs to Handcuffs
  • What a Vendor’s Mole Signals for Threat Intelligence

Speaking at security firm SentinelOne’s LABScon research conference on September 20, Google Threat Intelligence Group researcher Austin Larsen disclosed that an undercover Mandiant analyst had been embedded in TeamPCP’s private planning channel, a group chat the hackers called CanisterWorm, since roughly March 2026, near the start of the group’s public campaign. The analyst was one of about a dozen people with access to that channel. According to Larsen’s account, reported by WIRED’s Andy Greenberg and republished by Ars Technica, the infiltration let Google monitor the hacking spree from the inside, warn breach targets before extortion demands arrived, and eventually pass identifying details to law enforcement that helped lead to this year’s arrests.

What TeamPCP Actually Did

TeamPCP first surfaced online in late 2025 and built its campaign around a repeating trick: compromise one widely trusted open-source security tool, use the credentials and access that produces to compromise the next one, then repeat. Researchers at Endor Labs trace the pattern to a February 28, 2026 compromise of Aqua Security’s Trivy vulnerability scanner through a workflow exploit that led to a full repository takeover. The group returned on March 19 using residual access to push backdoored binaries to GitHub Releases, Docker Hub, GHCR, and Amazon ECR, moved through the npm ecosystem on March 20, hijacked all 35 of Checkmarx’s KICS GitHub Action tags on March 23, and shipped two malicious versions of the LiteLLM AI gateway, a project with roughly 95 million monthly downloads, on March 24.

From there the group’s reach kept expanding. It compromised the web app library TanStack and infrastructure at Mistral AI, then used the access those breaches produced to reach GitHub itself, data-contracting firm Mercor, and employee devices at OpenAI and the European Commission. At points the group automated the process with a self-spreading worm it called Mini Shai-Hulud, a nod to the sandworms in Dune and to an earlier, unrelated Shai-Hulud worm from September 2025. By the time investigators tallied the damage, TeamPCP’s campaign had touched more than 1,000 organizations, stolen an estimated 500,000 credentials, exfiltrated at least 300GB of data, and left victims with remediation costs Australian and US authorities have put in the hundreds of millions of dollars.

Building Trust From Nearly Day One

What makes this story unusual is not the scale of the breach, it is who was watching it happen. Larsen told WIRED that a Mandiant persona had spent months cultivating trust with someone who was later invited to join TeamPCP’s inner circle. “One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group,” Larsen said. “So essentially, almost day one, Mandiant was watching everything behind the scenes.”

The analyst’s access extended to CanisterWorm, where members boasted about the scope of what they had done. “You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history,” one TeamPCP member wrote in chat logs later reviewed by Google. Michael Fletcher, a former Australian Federal Police (AFP) analyst who now works in threat research at an Australian telecom firm, told WIRED he had approached Larsen around that time for advice on monitoring the group, and that Larsen warned him to proceed carefully because one member was a “friendly.” Fletcher’s reaction: “I thought, damn, you all have been inside this early.”

The access was not purely observational. Larsen says the undercover analyst eventually reached a server where TeamPCP stored the credentials, access tokens, and passwords it had stolen from its victims, intelligence Google says it used to warn some targets before the group could act on what it had taken.

A Criminal Partner Turns Informant

TeamPCP’s inside view was not limited to Google’s own persona. The group had partnered at points with ShinyHunters, a separate and better-known extortion crew that this site covered last month over a breach that padded its claimed Carhartt data with millions of synthetic records. According to Larsen, ShinyHunters later turned on its former partner and fed Google additional identifying details about TeamPCP’s members, an unusual instance of one criminal group informing on another, whether out of self-interest, a falling out, or some mix of both that Google’s account does not fully explain.

From Chat Logs to Handcuffs

Google’s own account describes following a trail of operational security mistakes made by one of the group’s alleged members and passing what it learned to law enforcement. Separately, researchers at the threat intelligence firm Flare ran their own investigation, tracing suspect Ruben Ian Thomson through a GitHub alias, bug-bounty program accounts, and a Steam profile that used the same cat avatar image later spotted on TeamPCP’s Telegram identity. CyberScoop reported that Flare’s correlation let it conclude with high confidence that Thomson ran the group.

The Australian Federal Police and FBI, working alongside Western Australia Police in an investigation that began in April 2026, arrested Thomson, 21, and Louis Michael Gaebler, 23, on August 26. Thomson faces eight charges, including four counts of unauthorized data modification, dealing in criminal proceeds worth more than $100,000, and refusing to comply with a device password disclosure order. Gaebler faces six related charges. FBI Assistant Director for the Cyber Division Brett Leatherman said in a statement: “These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide.”

What a Vendor’s Mole Signals for Threat Intelligence

Security vendors have shared indicators of compromise and threat-actor writeups for years. What Larsen described at LABScon is a different category of work: a private company building a persona, embedding it inside a criminal group’s actual planning channel, and sustaining that access for roughly six months, the kind of human intelligence operation historically associated with intelligence agencies rather than cloud security subsidiaries. That it worked at all says as much about TeamPCP’s own carelessness (members who boasted openly in chat about the scope of their own crimes, a suspect who reused the same cat avatar across GitHub, Steam, and Telegram) as it does about Mandiant’s tradecraft.

It also does not obviously scale. TeamPCP earned this level of attention because it was unusually loud and unusually damaging, not because embedding a mole is now a routine defensive tool available to every breached organization. Most software supply-chain attacks, including the npm worm ChainDrop and a later Shai-Hulud-linked PyPI wave this site tracked in June, part of the same worm family that lent TeamPCP’s own worm its name, get worked by automated detection and incident response, not six-month undercover placements. Docker’s own response to the March Trivy and Checkmarx compromises, building hardened images further down the stack, is the more typical defensive playbook: harden the pipeline so a single stolen credential cannot cascade, rather than infiltrate the group stealing it.

What the arrests do confirm is that TeamPCP’s roughly dozen-person inner circle is far larger than the two people now facing charges. Thomson and Gaebler appeared in Perth Magistrates Court on August 27, where a magistrate denied Thomson bail over concerns he might tamper with evidence and a prosecutor described the pair as the syndicate’s “masterminds” during the bail hearing. The rest of CanisterWorm’s roughly dozen participants, including whoever wrote the boast about the biggest supply chain attack in modern history, has not been named. Whether that changes, and whether other vendors follow Mandiant’s playbook the next time a criminal group gets this loud, is the open question LABScon’s audience was left with.

Tags:

CybersecurityGoogleOpen Source SecuritySoftware Supply Chain SecurityThreat Intelligence

Share

U.S. Space Force Guardians stand in formation during a ceremony, the branch Trump says his new AI Force will be modeled after
Previous Post

Trump Announces an AI Force and AI Czar, Calls Extinction Warnings a “Hoax”

A leaf insect camouflaged to look exactly like a leaf, with only its eyes revealing it is a living creature
Next Post

How to Detect npm Packages That Hide Malware in Runtime Code, Not Install Scripts

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
27 Sep
How to Build a Skip List in Python to Get Balanced-Tree Speed Without the Rotations
27 Sep
Red Hat’s RHEL 10 STIG Update Turns Compliance Into a Moving Target
Trending
September 27, 2026
How to Build a Skip List in Python to Get Balanced-Tree Speed Without the Rotations
September 27, 2026
Red Hat’s RHEL 10 STIG Update Turns Compliance Into a Moving Target
September 27, 2026
CISA Orders Federal Agencies to Patch a SharePoint RCE Flaw Microsoft First Called Spoofing
September 26, 2026
How to Build a Trie From Scratch in Python for Fast Prefix Search and Autocomplete
September 26, 2026
AI-Made Fake Cards Turn an Old Mail Scam Into a Growing Fraud Wave
September 26, 2026
OpenAI Pauses Training of Its Most Capable Models for the Second Time in Three Months

Related Posts

Blue-lit server racks in a modern data center, illustrating the compute infrastructure behind the AI boom.
Articles

The AI Boom Is Spending Real Money Before Proving Real Returns

June 7, 2026
Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Technician working with a laptop beside server racks, representing enterprise AI retrieval infrastructure
Articles

Google’s Agentic RAG Push Makes Enterprise AI Less of a One-Shot Guess

June 7, 2026
A person with a laptop and smartphone, representing digital attention and AI-assisted work
Articles

AI Chatbots Are Making Attention a Design Problem

June 7, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026