Google’s TeamPCP Mole Turns Threat Intelligence Into a Spy Operation
Google's threat intelligence group says an undercover analyst spent months inside a supply-chain hacking gang's private channel, helping identify two Australian suspects now facing criminal charges.
Before Australian police arrested two men in the Perth suburbs of Cottesloe and Mandurah on August 26, 2026, the hacking group known as TeamPCP had spent months tearing through the open-source software supply chain, using each compromised tool to steal the credentials needed to compromise the next one. What victims and outside researchers did not know until this week is that Google had someone on the inside almost the entire time.
Table Of Content
Speaking at security firm SentinelOne’s LABScon research conference on September 20, Google Threat Intelligence Group researcher Austin Larsen disclosed that an undercover Mandiant analyst had been embedded in TeamPCP’s private planning channel, a group chat the hackers called CanisterWorm, since roughly March 2026, near the start of the group’s public campaign. The analyst was one of about a dozen people with access to that channel. According to Larsen’s account, reported by WIRED’s Andy Greenberg and republished by Ars Technica, the infiltration let Google monitor the hacking spree from the inside, warn breach targets before extortion demands arrived, and eventually pass identifying details to law enforcement that helped lead to this year’s arrests.
What TeamPCP Actually Did
TeamPCP first surfaced online in late 2025 and built its campaign around a repeating trick: compromise one widely trusted open-source security tool, use the credentials and access that produces to compromise the next one, then repeat. Researchers at Endor Labs trace the pattern to a February 28, 2026 compromise of Aqua Security’s Trivy vulnerability scanner through a workflow exploit that led to a full repository takeover. The group returned on March 19 using residual access to push backdoored binaries to GitHub Releases, Docker Hub, GHCR, and Amazon ECR, moved through the npm ecosystem on March 20, hijacked all 35 of Checkmarx’s KICS GitHub Action tags on March 23, and shipped two malicious versions of the LiteLLM AI gateway, a project with roughly 95 million monthly downloads, on March 24.
From there the group’s reach kept expanding. It compromised the web app library TanStack and infrastructure at Mistral AI, then used the access those breaches produced to reach GitHub itself, data-contracting firm Mercor, and employee devices at OpenAI and the European Commission. At points the group automated the process with a self-spreading worm it called Mini Shai-Hulud, a nod to the sandworms in Dune and to an earlier, unrelated Shai-Hulud worm from September 2025. By the time investigators tallied the damage, TeamPCP’s campaign had touched more than 1,000 organizations, stolen an estimated 500,000 credentials, exfiltrated at least 300GB of data, and left victims with remediation costs Australian and US authorities have put in the hundreds of millions of dollars.
Building Trust From Nearly Day One
What makes this story unusual is not the scale of the breach, it is who was watching it happen. Larsen told WIRED that a Mandiant persona had spent months cultivating trust with someone who was later invited to join TeamPCP’s inner circle. “One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group,” Larsen said. “So essentially, almost day one, Mandiant was watching everything behind the scenes.”
The analyst’s access extended to CanisterWorm, where members boasted about the scope of what they had done. “You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history,” one TeamPCP member wrote in chat logs later reviewed by Google. Michael Fletcher, a former Australian Federal Police (AFP) analyst who now works in threat research at an Australian telecom firm, told WIRED he had approached Larsen around that time for advice on monitoring the group, and that Larsen warned him to proceed carefully because one member was a “friendly.” Fletcher’s reaction: “I thought, damn, you all have been inside this early.”
The access was not purely observational. Larsen says the undercover analyst eventually reached a server where TeamPCP stored the credentials, access tokens, and passwords it had stolen from its victims, intelligence Google says it used to warn some targets before the group could act on what it had taken.
A Criminal Partner Turns Informant
TeamPCP’s inside view was not limited to Google’s own persona. The group had partnered at points with ShinyHunters, a separate and better-known extortion crew that this site covered last month over a breach that padded its claimed Carhartt data with millions of synthetic records. According to Larsen, ShinyHunters later turned on its former partner and fed Google additional identifying details about TeamPCP’s members, an unusual instance of one criminal group informing on another, whether out of self-interest, a falling out, or some mix of both that Google’s account does not fully explain.
From Chat Logs to Handcuffs
Google’s own account describes following a trail of operational security mistakes made by one of the group’s alleged members and passing what it learned to law enforcement. Separately, researchers at the threat intelligence firm Flare ran their own investigation, tracing suspect Ruben Ian Thomson through a GitHub alias, bug-bounty program accounts, and a Steam profile that used the same cat avatar image later spotted on TeamPCP’s Telegram identity. CyberScoop reported that Flare’s correlation let it conclude with high confidence that Thomson ran the group.
The Australian Federal Police and FBI, working alongside Western Australia Police in an investigation that began in April 2026, arrested Thomson, 21, and Louis Michael Gaebler, 23, on August 26. Thomson faces eight charges, including four counts of unauthorized data modification, dealing in criminal proceeds worth more than $100,000, and refusing to comply with a device password disclosure order. Gaebler faces six related charges. FBI Assistant Director for the Cyber Division Brett Leatherman said in a statement: “These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide.”
What a Vendor’s Mole Signals for Threat Intelligence
Security vendors have shared indicators of compromise and threat-actor writeups for years. What Larsen described at LABScon is a different category of work: a private company building a persona, embedding it inside a criminal group’s actual planning channel, and sustaining that access for roughly six months, the kind of human intelligence operation historically associated with intelligence agencies rather than cloud security subsidiaries. That it worked at all says as much about TeamPCP’s own carelessness (members who boasted openly in chat about the scope of their own crimes, a suspect who reused the same cat avatar across GitHub, Steam, and Telegram) as it does about Mandiant’s tradecraft.
It also does not obviously scale. TeamPCP earned this level of attention because it was unusually loud and unusually damaging, not because embedding a mole is now a routine defensive tool available to every breached organization. Most software supply-chain attacks, including the npm worm ChainDrop and a later Shai-Hulud-linked PyPI wave this site tracked in June, part of the same worm family that lent TeamPCP’s own worm its name, get worked by automated detection and incident response, not six-month undercover placements. Docker’s own response to the March Trivy and Checkmarx compromises, building hardened images further down the stack, is the more typical defensive playbook: harden the pipeline so a single stolen credential cannot cascade, rather than infiltrate the group stealing it.
What the arrests do confirm is that TeamPCP’s roughly dozen-person inner circle is far larger than the two people now facing charges. Thomson and Gaebler appeared in Perth Magistrates Court on August 27, where a magistrate denied Thomson bail over concerns he might tamper with evidence and a prosecutor described the pair as the syndicate’s “masterminds” during the bail hearing. The rest of CanisterWorm’s roughly dozen participants, including whoever wrote the boast about the biggest supply chain attack in modern history, has not been named. Whether that changes, and whether other vendors follow Mandiant’s playbook the next time a criminal group gets this loud, is the open question LABScon’s audience was left with.








No Comment! Be the first one.