Close Menu
Tech News VisionTech News Vision
  • Home
  • What’s On
  • Mobile
  • Computers
  • Gadgets
  • Apps
  • Gaming
  • How To
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Trending Now
Security researchers used Claude to help them hack into OpenAI

Security researchers used Claude to help them hack into OpenAI

18 September 2026
An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang

An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang

18 September 2026
20th Anniversary Re-Release Gets New Trailer

20th Anniversary Re-Release Gets New Trailer

18 September 2026
Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact
Facebook X (Twitter) Instagram Pinterest VKontakte
Tech News VisionTech News Vision
  • Home
  • What’s On
  • Mobile
  • Computers
  • Gadgets
  • Apps
  • Gaming
  • How To
  • More
    • Web Stories
    • Global
    • Press Release
Tech News VisionTech News Vision
Home » An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang
What's On

An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang

News RoomBy News Room18 September 2026Updated:18 September 2026No Comments
Facebook Twitter Pinterest LinkedIn Tumblr Email
An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang

Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate that software supply chain hacking, and even released a Dune-themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies.

Now Google’s threat intelligence group has revealed that during a key moment of TeamPCP’s rampage, the company’s own undercover researcher had infiltrated the group—allowing Google to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group’s attempts to exploit those victims.

In a talk at the LABScon security research conference today, Google Threat Intelligence Group researcher Austin Larsen will present details on the company’s investigation—and infiltration—of TeamPCP amidst the group’s unprecedented, chaotic supply chain hacking campaign. According to Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hackers group and passed on key identifying details to law enforcement. The company also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with, but which later turned on the supply chain hackers. And perhaps most surprisingly, Larsen says that Google’s security subsidiary Mandiant had an undercover analyst—not himself—within the group’s inner circle from almost the beginning of TeamPCP’s time in the spotlight.

“One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group,” Larsen told WIRED in an interview ahead of his LABScon talk. “So essentially, almost day one, Mandiant was watching everything behind the scenes.”

The TeamPCP Mole

Late last month, Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early 20s, were arrested by Australian police in a joint investigation with assistance from the FBI, charged with hacking crimes, and described by the AFP—in a press release that, due to Australian privacy laws, did not name them—as “principal participants” in TeamPCP. The hacker group, which seems to have first appeared online in late 2025, had made headlines with a brazen string of cascading supply chain attacks: It repeatedly compromised open source software to hide its malware, which then allowed it to hijack the credentials of software developers and plant its malicious code in a yet another widely used tool, in a repeating cycle.

Starting this spring, for instance, TeamPCP compromised the open source security scanner Trivy, the AI application programming interface tool LiteLLM, infrastructure of the web application security firm Checkmarx, the web app library TanStack, and the enterprise AI platform Mistral AI. Those repeated supply chain attacks, with each enabling the group to cast its net again for more victims, ultimately allowed the hackers to breach open source code repository Github data contracting firm Mercor, employee devices at OpenAI, the European Commission, and many others who have remained unnamed in public reporting. At times, the group deployed a worm known as Mini Shai-Hulud, named after the sandworms in Dune, to automate its hacking and scale up to even more victims. (The name also seemed to refer to an earlier Shai-Hulud worm that hackers designed to try a similar approach in September of 2025, though it’s still not clear if TeamPCP or any of its alleged members were involved in that earlier intrusion campaign.)

Larsen now says that in March, just as TeamPCP was beginning its frenzied supply chain hacking, Google’s own undercover analyst was invited to join the hackers’ inner circle. That inside source, whose name Larsen declined to reveal, was one of about 12 members of the group given access to a core chat that TeamPCP called CanisterWorm.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

This cartridge-playing Game Boy clone is smaller and cheaper than Analogue’s Pocket

This cartridge-playing Game Boy clone is smaller and cheaper than Analogue’s Pocket

18 September 2026
If the AI Industry Followed Its Own Research, It Might Have Paused Already

If the AI Industry Followed Its Own Research, It Might Have Paused Already

18 September 2026
OpenAI discloses ‘concerning’ behaviours in its new models, unveils tracking tool

OpenAI discloses ‘concerning’ behaviours in its new models, unveils tracking tool

18 September 2026
Security researchers used Claude to help them hack into OpenAI

Security researchers used Claude to help them hack into OpenAI

18 September 2026
Editors Picks
This cartridge-playing Game Boy clone is smaller and cheaper than Analogue’s Pocket

This cartridge-playing Game Boy clone is smaller and cheaper than Analogue’s Pocket

18 September 2026
If the AI Industry Followed Its Own Research, It Might Have Paused Already

If the AI Industry Followed Its Own Research, It Might Have Paused Already

18 September 2026
OpenAI discloses ‘concerning’ behaviours in its new models, unveils tracking tool

OpenAI discloses ‘concerning’ behaviours in its new models, unveils tracking tool

18 September 2026
Former PlayStation Execs Recreate Iconic Disc-Sharing Xbox Diss

Former PlayStation Execs Recreate Iconic Disc-Sharing Xbox Diss

18 September 2026

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Trending Now
Tech News Vision
Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact
© 2026 Tech News Vision. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.