Mandiant analyst infiltrated TeamPCP as supply-chain attacks hit 1,000 firms
Google's threat intelligence group has revealed that one of its undercover analysts, operating through the security subsidiary Mandiant, infiltrated the hacker group TeamPCP from nearly the outset of its unprecedented supply-chain hacking campaign. The group breached over 1,000 companies by compromising hundreds of open-source programmes with malware, stealing developer credentials, and deploying an automated worm named Mini Shai-Hulud to scale attacks across critical infrastructure. Google's presence inside the group allowed the company to monitor attacks in real time, warn targets, and help disrupt exploitation attempts.
TeamPCP, which emerged online in late 2025, used a cascading attack strategy: compromising open-source tools such as Trivy, LiteLLM, and Checkmarx to steal developer credentials, then planting malicious code in additional widely-used software. The group's attacks ultimately breached GitHub, OpenAI, the European Commission, and numerous other organisations. Two alleged ringleaders—Australians Ruben Ian Thomson and Louis Michael Gaebler, both in their early 20s—were arrested late last month. Google passed intelligence to law enforcement based on identifying operational security mistakes made by the attackers, whilst also receiving information from ShinyHunters, a rival cybercriminal group that had initially partnered with TeamPCP but later turned against them.
- Google's undercover analyst monitored TeamPCP hacking from inside the group
- Supply-chain attacks breached over 1,000 companies via poisoned open-source code
- Two Australian alleged leaders arrested; Google aided law enforcement investigation
Americas Cybersecurity Technology World
Read the full article at the source →
Originally published by Ars Technica as “An undercover Google analyst infiltrated a notorious supply-chain hacking gang”.