In a development that sounds like a plot outline rejected for being too on-the-nose, Google's threat intelligence group has revealed that one of its own undercover researchers had infiltrated TeamPCP - the notorious supply-chain hacking gang - almost from the group's very first days in the spotlight. The company monitored the hacking spree from the inside, warned breach targets, and even helped disrupt the group's attempts to exploit victims.
The hacker group TeamPCP, before two alleged members were arrested and charged in Australia last month, carried out what Ars Technica describes as a hacking spree unlike any other in history. It tainted hundreds of open-source programs with malware, stole developer accounts to perpetuate that software supply-chain hacking, and even released a Dune-themed self-spreading worm to automate the process - ultimately breaching more than a thousand companies. Nothing says "we're the bad guys" quite like naming your worm after sandworms, but here we are.
At security firm SentinelOne's LABScon research conference today, Google Threat Intelligence Group researcher Austin Larsen will present details on the company's investigation - and infiltration - of TeamPCP. According to Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hacker group and passed on key identifying details to law enforcement. The company also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with, but which later turned on the supply-chain hackers. And perhaps most surprisingly, Larsen says Google's security subsidiary Mandiant had an undercover analyst - not himself - within the group's inner circle from almost the beginning of TeamPCP's time in the spotlight.
"One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group," Larsen told WIRED in an interview ahead of his LABScon talk. "So essentially, almost day one, Mandiant was watching everything behind the scenes." Because nothing builds trust like a fake identity and months of patient deception - which, to be fair, is also how most LinkedIn networking works.
Late last month, Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early 20s, were arrested by Australian police in a joint investigation with assistance from the FBI, charged with hacking crimes, and described by the Australian Federal Police (AFP) - in a press release that, due to Australian privacy laws, did not name them - as "principal participants" in TeamPCP. The hacker group, which seems to have first appeared online in late 2025, had made headlines with a brazen string of cascading supply-chain attacks: It repeatedly compromised open-source software to hide its malware, which then allowed it to hijack the credentials of software developers and plant its malicious code in yet another widely used tool, in a repeating cycle. It's like a pyramid scheme, but for malware - and with worse exit opportunities.
Starting this spring, for instance, TeamPCP compromised the open-source security scanner Trivy, the AI application programming interface tool LiteLLM, infrastructure of the web application security firm Checkmarx, the web app library TanStack, and the enterprise AI platform Mistral AI. Those repeated supply-chain attacks, with each enabling the group to cast its net again for more victims, ultimately allowed the hackers to breach open-source code repository GitHub, data contracting firm Mercor, and employee devices at OpenAI, the European Commission, and many others who have remained unnamed in public reporting. At times, the group deployed a worm known as Mini Shai-Hulud, named after the sandworms in Dune, to automate its hacking and scale up to even more victims. (The name also seemed to refer to an earlier Shai-Hulud worm that hackers designed to try a similar approach in September 2025, though it's still not clear if TeamPCP or any of its alleged members were involved in that earlier intrusion campaign.) Because if you're going to commit international cybercrime, you might as well do it with a sci-fi reference.
Larsen now says that in March, just as TeamPCP was beginning its frenzied supply-chain hacking, Google's own undercover analyst was invited to join the hackers' inner circle. That inside source, whose name Larsen declined to reveal, was one of about 12 members of the group given access to a core chat that TeamPCP called CanisterWorm. Twelve people in a secret criminal chat room, and one of them is a Google employee. That's not a hacker collective; that's a group project where one member is definitely doing all the work.
One of those cybercriminal partners was ShinyHunters, a years-old, highly prolific hacker group that has extorted millions of dollars from victims through data theft and ransomware, including in the breach of educational software platform Canvas that would later paralyze thousands of schools across the US. Around April, a few weeks after partnering with TeamPCP, ShinyHunters went rogue, Larsen says, carrying out its own extortions with TeamPCP's credentials but without giving the supply-chain hackers their cut. ShinyHunters went so far as to share with Larsen, unsolicited, a full log of the group's chat on TeamPCP's server - not knowing that he already had access via Google's mole. So to recap: Google had a spy in the group, and a rival criminal organization was also feeding them evidence, apparently for free. TeamPCP's operational security was less a fortress and more a screen door.
This story originally appeared on wired.com.