Earlier than two of its alleged members have been arrested and charged in Australia final month, the hacker group often called TeamPCP carried out a hacking spree in contrast to every other in historical past. It tainted a whole bunch of open-source packages with its malware, stole developer accounts to perpetuate that software program provide chain hacking, and even launched a Dune-themed self-spreading worm to automate the method, in the end breaching greater than a thousand firms.
Now Google’s risk intelligence group has revealed that in a key second of TeamPCP’s rampage, the corporate’s personal undercover researcher had infiltrated the group—permitting Google to watch the hacking spree from the within, warn breach targets, and even assist disrupt the group’s makes an attempt to use these victims.
In a chat on the LABScon safety analysis convention at present, Google Menace Intelligence Group researcher Austin Larsen will current particulars on the corporate’s investigation—and infiltration—of TeamPCP amidst the group’s unprecedented, chaotic provide chain hacking marketing campaign. In response to Larsen, Google ultimately adopted a path of operational safety errors allegedly made by one of many two Australians now accused of being main members of the hackers group and handed on key figuring out particulars to regulation enforcement. The corporate additionally acquired intelligence from ShinyHunters, one other notorious cybercriminal group that TeamPCP partnered with, however which later turned on the availability chain hackers. And maybe most surprisingly, Larsen says that Google’s safety subsidiary Mandiant had an undercover analyst—not himself—throughout the group’s interior circle from nearly the start of TeamPCP’s time within the highlight.
“One in every of our personas had been working for a lot of months to construct belief with one of many actors that was invited to hitch TeamPCP, and so was added to the group,” Larsen informed WIRED in an interview forward of his LABScon speak. “So primarily, nearly day one, Mandiant was watching all the pieces behind the scenes.”
The TeamPCP Mole
Late final month, Ruben Ian Thomson and Louis Michael Gaebler, each Australians of their early 20s, have been arrested by Australian police in a joint investigation with help from the FBI, charged with hacking crimes, and described by the AFP—in a press launch that, attributable to Australian privateness legal guidelines, didn’t title them—as “principal contributors” in TeamPCP. The hacker group, which appears to have first appeared on-line in late 2025, had made headlines with a brazen string of cascading provide chain assaults: It repeatedly compromised open supply software program to cover its malware, which then allowed it to hijack the credentials of software program builders and plant its malicious code in a yet one more extensively used software, in a repeating cycle.
Beginning this spring, as an illustration, TeamPCP compromised the open supply safety scanner Trivy, the AI software programming interface software LiteLLM, infrastructure of the online software safety agency Checkmarx, the online app library TanStack, and the enterprise AI platform Mistral AI. These repeated provide chain assaults, with every enabling the group to forged its internet once more for extra victims, in the end allowed the hackers to breach open supply code repository Github knowledge contracting agency Mercor, worker units at OpenAI, the European Fee, and lots of others who’ve remained unnamed in public reporting. At occasions, the group deployed a worm often called Mini Shai-Hulud, named after the sandworms in Dune, to automate its hacking and scale as much as much more victims. (The title additionally appeared to seek advice from an earlier Shai-Hulud worm that hackers designed to strive the same method in September of 2025, although it’s nonetheless not clear if TeamPCP or any of its alleged members have been concerned in that earlier intrusion marketing campaign.)
Larsen now says that in March, simply as TeamPCP was starting its frenzied provide chain hacking, Google’s personal undercover analyst was invited to hitch the hackers’ interior circle. That inside supply, whose title Larsen declined to disclose, was one in every of about 12 members of the group given entry to a core chat that TeamPCP known as CanisterWorm.








