Undercover Google analyst infiltrated TeamPCP supply‑chain hacking crew
Inside access let Google track TeamPCP’s attacks on open‑source projects and help blunt their impact.
Google’s Threat Intelligence Group revealed that during the height of the TeamPCP supply‑chain attacks, an undercover analyst from its Mandiant subsidiary infiltrated the gang’s inner circle, giving Google inside visibility into the operation. TeamPCP had compromised hundreds of open‑source projects, stolen developer credentials, and used a Dune‑themed self‑propagating worm to breach more than 1,000 organizations, making it a major software supply‑chain incident. Using data from this infiltration, Google monitored the campaign in real time, warned affected targets, and helped interfere with TeamPCP’s exploitation attempts. Researcher Austin Larsen is presenting the technical and investigative details of this operation at SentinelOne’s LABScon security conference. Google says it correlated the hackers’ operational security errors with additional intelligence from the cybercrime group ShinyHunters, then provided identifying information about an alleged Australian ringleader to law enforcement, preceding two arrests in Australia.
Why it matters
For developers, TeamPCP shows how widely a compromised open‑source dependency can spread, with hundreds of tainted projects and more than a thousand breached organizations. Google’s move to embed an undercover analyst inside the group meant it could watch attacks unfold, warn affected teams, and disrupt some exploitation attempts in progress. The case underlines both the risks of relying on public packages and the value of real‑time threat intelligence tied directly into software supply chains.