One of the twelve people in the TeamPCP hacking gang's most secretive chat channel was secretly working for Google. For months, an undercover analyst watched the group plan a supply chain hacking campaign its own members described as the largest ever recorded, according to Google threat intelligence researcher Austin Larsen, who detailed the operation in a talk at SentinelOne's LABScon security conference.
The operation was first reported by Wired and republished on Ars Technica. TeamPCP's supply chain hacking spree tainted hundreds of open-source programs with malware, stole developer accounts to keep the infection spreading, and breached more than a thousand companies.
The mole inside CanisterWorm
TeamPCP, the crew behind one of the biggest supply chain hacking waves on record, first appeared online in late 2025. By early 2026, Google's Threat Intelligence Group had a plan to get inside. A Mandiant analyst, operating under a Google-created online persona, spent months building trust with a hacker who was later invited to join TeamPCP, giving Google a view inside the supply chain hacking operation from the start. When that actor was brought into the gang's core chat, a roughly twelve-person channel called CanisterWorm, Google's person came along too.
Larsen declined to name the analyst. He said the mole joined the inner circle in March 2026, just as TeamPCP's supply chain hacking campaign was getting started, and stayed nearly from day one. The role was strictly observational. Larsen said the analyst never carried out illegal hacking or encouraged anyone to break in, describing the position as a fly on the wall who said only enough to avoid suspicion, with strict limits on what the team would do.
What the gang broke into
From inside the chat, Google watched TeamPCP run a cascading supply chain hacking operation. The gang poisoned popular open-source software in a supply chain hacking blitz, then used the stolen developer credentials from each breach to compromise more projects, repeating the cycle. They also released a self-spreading worm called Mini Shai-Hulud, named after the giant sandworms in Dune, possibly connected to an earlier worm called Shai-Hulud that surfaced in September 2025, though that link remains unclear.
The named targets show how wide the supply chain hacking net went. TeamPCP compromised the open-source security scanner Trivy, the AI API tool LiteLLM, the infrastructure of web app security firm Checkmarx, the web app library TanStack, and the enterprise AI platform Mistral AI. Breaches linked to the group reached GitHub, data contracting firm Mercor, and employee devices at OpenAI and the European Commission, alongside many victims that have not been named publicly.
How Google used the access
The mole found a server holding TeamPCP's trove of stolen victim credentials: usernames, passwords, and access tokens the gang planned to use for extortion. Warning thousands of victims one by one would have been too slow, so Google went to the providers first, contacting companies including Amazon Web Services and Microsoft to revoke the stolen credentials, then sending hundreds of notification emails to providers and victims. Many of those warnings got immediate responses, Larsen said, The revocations disrupted the supply chain hacking campaign by cutting off the stolen credentials it needed for extortion.
The undercover access also stopped a different kind of attack before it launched, beyond the supply chain hacking itself. Google learned through the chat that a TeamPCP member was using an AI tool to develop a zero-day exploit against widely used login software, one designed to bypass two-factor authentication. Google obtained the exploit code, tested it, and confirmed it worked with some adjustments. The company then warned the software's developer, who issued a patch. Google had described the incident in a case study published in May 2026 without naming TeamPCP or revealing where the intelligence came from.
Partners, betrayals, and arrests
TeamPCP did not operate alone. Around April 2026, the prolific cybercriminal group ShinyHunters partnered with the gang, then went rogue: it ran its own extortion operations without sharing the proceeds and, without realizing Google already had a mole in place, handed Larsen a full log of TeamPCP's server chat. ShinyHunters then taunted TeamPCP on X. Spooked, TeamPCP narrowed its inner circle, moved its data to a new server, and exiled ShinyHunters and several others from CanisterWorm, including Google's undercover analyst.
The gang's cover did not last. Larsen traced one CanisterWorm handle to the Gmail address [email protected] through a BreachForums data leak, then connected the sheepstealing alias to a PayPal account linked to [email protected] via a dispute on a forum dating back to 2019. When TeamPCP's data moved to a new provider, Google learned through a trusted partner that it was being backed up to a Google Drive tied to that same Gmail account. Larsen passed the tip to the FBI. About a month later, after United States law enforcement obtained Thomson's data from Google through a warrant, Ruben Ian Thomson was arrested; video of the arrest showed him being walked out of a suburban home in a Northface hoodie and sweatpants.
Thomson and Louis Michael Gaebler, both Australians in their early twenties, were arrested, closing out a supply chain hacking investigation that spanned Australia and the United States by Australian police in late August 2026 in a joint investigation conducted with FBI assistance, and charged with hacking crimes. The Australian Federal Police described the pair, without naming them because of Australian privacy laws, as principal participants in TeamPCP. According to the AFP, the group held more than half a million users' credentials, though Larsen estimated the gang collected only tens of thousands of dollars in extortion payments, far less than the millions such operations sometimes yield.
Others had been closing in as well. Michael Fletcher, a former AFP analyst now doing threat research at an Australian telecom firm, said Larsen asked him to approach the hackers cautiously because one of them was considered a friendly. Cybersecurity journalist Brian Krebs published his own investigation laying out clues pointing to Thomson's identity. The FBI declined to comment, citing an active investigation, and the AFP declined as well. Neither Thomson nor Gaebler could be reached for comment.
A shift toward supply chain hacking disruption
The operation reflects a change in how Google's Threat Intelligence Group works. Larsen said the team is focusing more on actively disrupting cybercrime and state-sponsored hacking, including through a newly launched Cyber Disruption Unit, rather than only publishing research. As he put it: "Writing reports can only be so useful." The next step, he said, is taking action to protect users and customers, a philosophy the TeamPCP infiltration put into practice.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.