Google Analyst Infiltrated TeamPCP and Helped Disrupt Its Supply-Chain Attacks
Google Threat Intelligence Group has revealed that a Mandiant analyst infiltrated TeamPCP, a hacking group accused of carrying out an unusually extensive series of software supply-chain attacks. The analyst spent months building trust with a TeamPCP member and gained access to an internal chat used by roughly a dozen people at the center of the operation. This access gave Google visibility into the group’s activities and helped the company warn potential victims and disrupt further attacks.
TeamPCP, which appears to have emerged online in late 2025, repeatedly compromised open-source software and developer accounts to distribute malware and obtain additional credentials. Its targets reportedly included tools and companies such as Trivy, LiteLLM, Checkmarx, TanStack, and Mistral AI. The campaign eventually affected more than a thousand companies and exposed credentials belonging to hundreds of thousands of users. The group also used a self-spreading worm called Mini Shai-Hulud to automate parts of the operation.
Google says its undercover analyst discovered a server containing stolen usernames, passwords, and access tokens. Rather than contacting every affected organization individually, Google first worked with major service providers, including Amazon Web Services and Microsoft, to revoke compromised credentials and limit the hackers’ ability to use them. Google also discovered an AI-assisted zero-day exploit being developed by someone in the group’s circle. After testing the exploit, Google alerted the affected software developer, who patched the vulnerability.
The investigation also benefited from a split between TeamPCP and the cybercriminal group ShinyHunters, which provided Google with chat logs. Separately, Google researchers traced digital clues linking a TeamPCP member to an email account and a Google Drive containing stolen material. The information was passed to the FBI and contributed to the investigation that preceded the arrests in Australia of Ruben Ian Thomson and Louis Michael Gaebler. Google says its undercover analyst did not participate in illegal hacking and only observed the group’s activities while maintaining the cover.
