An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang

In a sophisticated counterintelligence operation that has redefined the landscape of corporate threat defense, Google’s Threat Intelligence Group successfully embedded an undercover operative within the inner circle of TeamPCP, a prolific hacker collective responsible for one of the most audacious software supply-chain compromise campaigns in modern history. The revelation, detailed by researcher Austin Larsen at the SentinelOne LABScon conference, marks a pivotal moment in the industry’s shift from passive detection to active, aggressive disruption of cybercriminal syndicates.
The investigation into TeamPCP, which culminated in the arrest of two Australian nationals last month, provides a rare look at how major tech conglomerates are increasingly utilizing human intelligence to dismantle threats before they scale. For months, this undercover analyst—a Mandiant employee acting on behalf of Google—monitored the group’s internal communications, thwarted extortion attempts, and provided critical intelligence that led law enforcement directly to the hackers’ doorsteps.
The Rise of TeamPCP: A Cascade of Compromise
TeamPCP emerged in late 2025 as a disruptive force, utilizing a methodology known as cascading supply-chain attacks. Unlike traditional breaches that target a single enterprise, TeamPCP focused on the software ecosystem itself. By tainting open-source libraries and hijacking developer credentials, the group turned trusted tools into vectors for malware delivery. This "pollute-the-well" approach allowed the hackers to move laterally across the tech industry with unprecedented speed.
Throughout the spring of 2026, the group systematically compromised a series of high-profile platforms, including the open-source security scanner Trivy, the AI API tool LiteLLM, the infrastructure of security firm Checkmarx, the library manager TanStack, and the enterprise AI giant Mistral AI. By compromising these gateways, TeamPCP gained access to downstream targets, including GitHub, the data firm Mercor, and internal devices at organizations as sensitive as OpenAI and the European Commission.
Central to their operational efficiency was the deployment of a self-spreading worm dubbed "Mini Shai-Hulud." Named after the fictional sandworms of the Dune universe, this malicious code was designed to automate the scanning and infection of software packages, effectively scaling the group’s reach from a boutique operation to a widespread automated threat.

The Anatomy of an Infiltration
The success of Google’s intervention was rooted in patience. According to Austin Larsen, the Mandiant analyst managed to build trust with an unsuspecting TeamPCP recruit over several months. By March 2026, the operative had secured an invitation to "CanisterWorm," a restricted, 12-member chat group that served as the command-and-control hub for TeamPCP’s leadership.
Once inside, the operative functioned as a "fly on the wall," meticulously logging the group’s activities while adhering to strict ethical and legal guardrails to ensure no illegal actions were performed on behalf of the company. The intelligence gathered was profound. The team discovered that TeamPCP was not merely stealing data but was also actively developing a zero-day exploit using generative AI. This exploit targeted login software to bypass two-factor authentication. By acquiring the code, Google was able to verify the threat and coordinate with the affected developer to release a patch before the exploit could be weaponized at scale.
Betrayal Among Thieves: The ShinyHunters Factor
The stability of TeamPCP’s internal structure was short-lived, largely due to its own attempts to monetize its stolen data. Despite holding credentials for over 500,000 users, the group struggled to generate the multi-million-dollar payouts seen by more established cyber-syndicates. In an effort to boost their revenue, they entered into a partnership with ShinyHunters, a notorious group known for massive data breaches.
The alliance proved disastrous for TeamPCP. In April, ShinyHunters effectively went rogue, utilizing TeamPCP’s stolen credentials for their own extortion schemes without sharing the profits. In an act of sheer hubris, ShinyHunters shared logs of TeamPCP’s own internal chats with researchers, unaware that Google already had a permanent, direct line into that same data. This internecine conflict created a chaotic environment that further exposed the hackers’ poor operational security (opsec).
The Digital Breadcrumbs to an Arrest
The transition from online monitoring to physical arrest required a combination of digital forensics and tactical timing. The primary break in the case occurred when Larsen identified a recurring alias, "sheepstealing," linked to the CanisterWorm chat. Through historical data from the BreachForums hacker site, investigators traced the alias to a PayPal account associated with an email address: [email protected].
The final piece of evidence emerged when TeamPCP migrated their stolen cache to a new server, which they inadvertently backed up to a Google Drive account tied to the same email address. The sheer carelessness of this action allowed Google to verify the identity of the user behind the "sheepstealing" handle. The information was promptly handed to the FBI and subsequently to the Australian Federal Police (AFP).

In late August 2026, Australian authorities arrested Ruben Ian Thomson and Louis Michael Gaebler. Footage of the arrest in a quiet suburban home stood in stark contrast to the sophisticated, high-stakes digital warfare the pair had been waging just weeks prior.
Strategic Implications for Cybersecurity
The TeamPCP operation represents a fundamental shift in the defensive posture of big tech. With the recent formation of Google’s "Cyber Disruption Unit," the company is signaling that the era of merely observing or reporting on threats is over. The unit is explicitly tasked with identifying and intervening in criminal activity, even if that intervention requires deep-cover human intelligence or the proactive disruption of infrastructure.
However, this proactive approach is not without risks. Critics of such operations often point to the "grey area" of infiltrating criminal organizations. Security analysts note that while the disruption of TeamPCP undoubtedly protected thousands of organizations, the reliance on an undercover operative requires absolute transparency and rigid oversight to prevent the "blurring of lines" between ethical research and prohibited activity.
Furthermore, the case serves as a wake-up call for the open-source community. The ease with which TeamPCP compromised multiple widely-used tools highlights the fragility of the software supply chain. As organizations continue to rely on a complex web of third-party libraries and APIs, the potential for a single compromised account to cause a systemic collapse remains a critical vulnerability.
Conclusion: A New Era of Active Defense
The downfall of TeamPCP is a testament to the power of intelligence-led security. By combining technical telemetry with human-centric investigative techniques, Google and its partners were able to neutralize a threat that could have caused incalculable damage to global enterprise. As cybercriminal groups grow more sophisticated and reliant on AI-driven exploits, the ability to infiltrate these inner circles—and the political and legal will to act on that intelligence—will likely become the defining feature of elite cybersecurity defense in the coming decade.
The arrests in Australia are likely not the end of the story. With the FBI’s new cyber strategy emphasizing partnerships with the private sector, the blueprint established by the TeamPCP investigation is expected to be replicated. For cybercriminals, the message is clear: the digital shadows they operate in are increasingly being illuminated by the very platforms they seek to exploit.







