An undercover Google analyst infiltrated a notorious supply chain hacking gang to dismantle a global cyber threat

In a striking revelation that underscores the escalating sophistication of modern cyber-espionage, Google’s threat intelligence division recently disclosed that it successfully embedded an undercover researcher within the inner circle of TeamPCP, a prolific hacker collective responsible for a string of unprecedented software supply chain attacks. This infiltration allowed the tech giant to monitor the group’s operations in real time, provide early warnings to threatened organizations, and ultimately assist law enforcement in identifying key figures behind a campaign that breached over a thousand companies worldwide.
The revelation was made public during the LABScon research conference hosted by SentinelOne, where Austin Larsen, a lead researcher at Google Threat Intelligence, detailed the months-long operation. The investigation into TeamPCP marks a significant pivot in corporate cybersecurity strategy, moving from passive defense and retrospective reporting to proactive, real-time disruption of criminal networks.
The Rise and Reach of TeamPCP
TeamPCP emerged as a significant threat in late 2025, quickly establishing a reputation for a specific and highly effective form of digital sabotage: software supply chain poisoning. By tainting legitimate open-source libraries and hijacking developer credentials, the group turned trusted tools into vectors for malware. This cascading approach allowed the group to compromise a wide range of high-profile targets, including the open-source security scanner Trivy, the AI-focused API tool LiteLLM, the web application security firm Checkmarx, the web library TanStack, and the enterprise AI platform Mistral AI.
The group’s methodology was notable for its automation. They frequently deployed a self-spreading worm, colloquially dubbed "Mini Shai-Hulud"—a reference to the sandworms in Frank Herbert’s Dune—to automate the infection of new systems and scale their reach. This campaign eventually facilitated unauthorized access to sensitive repositories at GitHub, the data contracting firm Mercor, and internal devices at major organizations like OpenAI and the European Commission.
Chronology of the Infiltration
The operation to monitor TeamPCP began in early 2026, shortly after the group gained momentum. According to Larsen, a Google/Mandiant analyst successfully established a digital persona that built enough trust within the hacker community to be invited into the group’s core communication channel, which they referred to as "CanisterWorm."

By March 2026, the analyst had secured a "fly on the wall" position among approximately 12 primary members of the collective. This access provided unprecedented visibility into the group’s operations, including their plans to monetize stolen data. The analyst’s presence was kept strictly passive; they were instructed to maintain a low profile, contributing just enough to remain credible without ever facilitating or encouraging illegal activities.
The timeline of the investigation accelerated throughout the spring and summer of 2026:
- March 2026: Google’s mole is admitted into the CanisterWorm chat.
- April 2026: TeamPCP attempts to monetize its massive trove of stolen credentials by partnering with the infamous hacker group ShinyHunters.
- April–May 2026: ShinyHunters betrays TeamPCP, sharing chat logs with researchers and acting independently, which leads to internal paranoia and the eventual exile of several members, including the Google mole.
- May 2026: Google publishes a case study regarding an AI-created zero-day exploit, which the company had discovered via its monitoring of TeamPCP, allowing the relevant software developers to patch the flaw before it could be weaponized on a massive scale.
- August 2026: Following a trail of operational security (OPSEC) failures, Google provides actionable intelligence to the FBI, leading to the identification and subsequent arrest of the primary suspects in Australia.
Operational Security Failures and Digital Fingerprints
Despite their technical prowess in exploiting supply chains, the members of TeamPCP ultimately succumbed to human error. Larsen’s team tracked the group’s activities by cross-referencing activity on the BreachForums hacker forum with other digital footprints. The primary breakthrough occurred when the handle "sheepstealing" was linked to a 2019 dispute involving a PayPal account registered to a name that eventually matched one of the accused, Ruben Ian Thomson.
Further carelessness allowed investigators to map the group’s data storage. When TeamPCP migrated its stolen credentials to a new server, the data was inadvertently backed up to a Google Drive account linked to the same email address, "[email protected]." This glaring lapse in operational security provided the "smoking gun" that enabled Google to provide definitive evidence to the FBI.
The Role of External Partnerships and Rivalries
The internal dynamics of the cybercriminal underground played a crucial role in the group’s downfall. TeamPCP’s attempt to increase its profit margins by partnering with the established criminal syndicate ShinyHunters backfired significantly. ShinyHunters, known for its previous role in the massive breach of the educational platform Canvas, decided to "go rogue."
By sharing the logs of TeamPCP’s internal servers with security researchers—unaware that Google already had a mole present—ShinyHunters inadvertently confirmed the data Google had already gathered. This betrayal created a climate of extreme distrust within TeamPCP, leading to the purging of the chat room and the removal of the undercover analyst. However, by that time, Google had already secured the necessary intelligence to protect its users and notify affected organizations.

Official Responses and Legal Developments
Late in August 2026, authorities in Australia executed a coordinated operation. Ruben Ian Thomson and Louis Michael Gaebler, both in their early 20s, were arrested by the Australian Federal Police (AFP) with the active support of the FBI. While Australian privacy laws prevented the immediate public identification of the suspects in local press releases, subsequent reports confirmed their status as the alleged leaders of the group.
The FBI has maintained a standard stance on the matter, declining to comment on specific active investigations while emphasizing its commitment to the new FBI Cyber Strategy, which prioritizes "impact" through public-private partnerships. The successful resolution of the TeamPCP case is widely viewed as a direct success of this collaborative model between big-tech security units and federal law enforcement.
Broader Implications for Cybersecurity
The infiltration of TeamPCP marks a turning point for the cybersecurity industry. Traditionally, threat intelligence has been reactive—analyzing logs after a breach has occurred. The establishment of Google’s "Cyber Disruption Unit" signals a shift toward a more aggressive posture. By actively participating in the disruption of malicious infrastructure, major technology firms are redefining their role as digital first-responders.
However, this proactive approach is not without its risks. The use of undercover personas requires strict ethical oversight to ensure that investigators do not cross the line into entrapment or illegal activity. Larsen emphasized that "guardrails" were in place to ensure that the Google analyst remained a silent observer, never participating in the group’s hacking efforts.
The case also highlights the growing threat of AI-assisted cybercrime. The fact that TeamPCP used AI to develop zero-day exploits indicates that the barrier to entry for high-level hacking is lowering. As automated tools become more accessible, the volume and velocity of supply chain attacks are expected to rise, necessitating even tighter cooperation between software vendors, security researchers, and global law enforcement.
In conclusion, the TeamPCP incident serves as a cautionary tale for both cybercriminals and security professionals. For the former, it demonstrates that even the most technically sophisticated operations are vulnerable to the human element—the inevitable mistakes in operational security that leave a trail for investigators. For the latter, it proves that the era of passive monitoring is ending, replaced by a new, more interventionist strategy where intelligence is a tool for active disruption rather than just historical record-keeping. As the digital landscape continues to evolve, the ability of organizations to infiltrate, analyze, and dismantle these networks from the inside will likely become the most critical component of modern global security.







