Breaking
Cyber CrimeDeveloping Story

Google's mole inside a hacking crew

Google's threat intelligence team says an undercover analyst spent months inside TeamPCP, watching a supply-chain spree from behind the scenes.

··2 hours ago·9 min read
laptop screen displaying colorful code
Photo by Mohammad Rahmani on Unsplash

For months, a supply-chain hacking crew known as TeamPCP ripped through open-source software, stole developer accounts, and pushed a self-spreading worm through the packages companies depend on. What the group did not know, according to Google's threat intelligence team, is that one of the roughly twelve people in its core chat had been placed there by Mandiant, Google's security subsidiary, from nearly the start.

The account of that infiltration came from Austin Larsen, a researcher at Google Threat Intelligence Group, in a talk at SentinelOne's LABScon research conference and in an interview with WIRED ahead of it. According to Larsen, the inside position let Google watch the campaign in real time, warn the companies whose credentials had been stolen, and interfere with the group's plans to profit from them.

A seat inside CanisterWorm

Google's presence in the group was not a last-minute insertion. Larsen said the persona had spent months building a relationship with someone who was later invited into TeamPCP, which is how the analyst got added to the crew's core chat, a channel the group called CanisterWorm.

“One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group,” Larsen told WIRED. “So essentially, almost day one, Mandiant was watching everything behind the scenes.”

— Austin Larsen, researcher at Google Threat Intelligence Group

Larsen declined to name the undercover analyst. He said the analyst never took part in hacking or encouraged the group's intrusions, describing the role as observational. “They were a fly on the wall, only saying enough to not be suspicious,” he said, adding that “there are guardrails around what we do.”

By Larsen's account, the infiltration began in March, just as TeamPCP was accelerating its supply-chain attacks. The access gave Google a view of the group's internal discussions, including one member's boast about the scale of the operation:

“You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history,” one TeamPCP member wrote in the leaked chats.

That message was quoted without a named individual attribution in the source material.

The credential trove and the race to revoke

Inside the group, Larsen said, Google's analyst reached a server where TeamPCP stored credentials taken from its victims — usernames, passwords, and access tokens that the crew appeared to be holding for extortion. With that store in view, Google's team weighed how to blunt the scheme rather than simply document it.

“My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen?” Larsen said. “Let's go mess up what they're doing. That was my goal.”

Notifying every victim company directly was not practical, Larsen said, because the number of breached organizations was too large. Instead, Google went first to the providers where the stolen credentials could be used, including Amazon Web Services and Microsoft, to get them revoked. Larsen and his team sent hundreds of notification emails to those providers and then to victims, and many drew immediate responses.

The AFP has said the group's collection of stolen data included more than half a million users' credentials. Despite that haul, Larsen estimated, TeamPCP was collecting only tens of thousands of dollars in extortion payments, far short of the millions that comparable groups have pulled in.

A partner that turned predator

Google was not the only party working against TeamPCP from inside its own orbit. To monetize its stolen data, the crew invited other cybercriminal groups to partner with it, handing over access to credentials in exchange for a cut of any extortion payments.

One of those partners was ShinyHunters, a prolific group that has extorted millions of dollars through data theft and ransomware, including in a breach of educational software platform Canvas that later disrupted thousands of schools in the US.

Around April, a few weeks after the partnership began, ShinyHunters went rogue, Larsen said, running its own extortions with TeamPCP's credentials and keeping the proceeds. ShinyHunters then shared a full log of TeamPCP's chat with Larsen, unsolicited, apparently unaware that Google already had a source in the room.

ShinyHunters also taunted TeamPCP in messages on X. The betrayal got the crew's attention: TeamPCP shrank its inner circle, moved its data to a new server, and removed ShinyHunters and several other members from the CanisterWorm chat, Google's analyst among them.

“Just delete that and stop sharing shit with shinyhunters,” one of the TeamPCP leaders wrote.

That message, too, was quoted without a named individual attribution in the source material.

Following a trail of digital residue

Losing the inside seat did not end the investigation. Larsen said conventional detective work filled the gap, starting with a leak of user data from the BreachForums hacker forum. There, one of the most active handles in the CanisterWorm chat had been registered to the Gmail address sheepstealing@gmail.com.

Other forum archives turned up a 2019 dispute between a user calling themselves sheepstealing and a seller of pirated Microsoft Office keys. In that dispute, the sheepstealing user asked for a refund to a PayPal account tied to the email ruben@thomsonfamily.net.au.

After TeamPCP moved its stolen credentials to a server hosted by another provider, Larsen said, Google learned some of what was on the new server through what he described as a “trusted partner,” and also that the server was being backed up to a Google Drive on the same sheepstealing@gmail.com account.

“When we saw that, I just thought: There's no way. Why would he be sending all of this illicit, stolen material to a Google Drive that's tied to himself?” Larsen said. “That's when we gave the tip to the FBI.”

Larsen said an agent responded with interest within minutes. About a month after the tip, he said, US law enforcement had completed the legal process of seeking data from Google with a warrant.

An AI-built exploit appears

While inside the chat, Larsen said, Google also learned that someone in the group's core circle was using an AI tool to develop a zero-day exploit in widely used login software — code that would have let the hackers bypass two-factor authentication. That work was separate from the crew's supply-chain hacking.

Google obtained a copy of the exploit, tested it, and found that it worked after minor adjustments, according to Larsen — a rare instance of an AI-created hacking technique exploiting a previously unknown software flaw. Google alerted the software's developer, who patched the vulnerability.

Google described the incident in a case study Google released in May, but without naming TeamPCP or explaining how the company learned of the exploit.

ShinyHunters, arrests, and outside sleuths

Google's not the only party that had been tracking the group's alleged members. Journalist and cybersecurity sleuth Brian Krebs published a story last month laying out his own set of clues that led to the identity of Ruben Ian Thomson.

According to the source material, Thomson and Louis Michael Gaebler, both Australians, were arrested by Australian police in a joint investigation with assistance from the FBI and charged with hacking crimes. The Australian Federal Police, in a press release that did not name them because of Australian privacy laws, described them as “principal participants” in TeamPCP. Australian police released video of Thomson being walked out of a suburban home in a Northface hoodie and sweatpants. Neither Thomson nor Gaebler could be reached for comment.

In a statement to WIRED, the FBI declined to comment on any “active investigation” but noted that it “is able to confirm we strive to increase impact on adversaries through partnerships as documented in our newly released FBI Cyber Strategy.” The AFP declined to comment.

The scope of the spree

TeamPCP's campaign, which appears to have first surfaced online in late 2025, worked as a repeating cycle: compromise open-source software to hide malware, use it to hijack developer credentials, then plant malicious code in another widely used tool. Starting this spring, the group compromised:

  • The open-source security scanner Trivy
  • The AI application programming interface tool LiteLLM
  • Infrastructure of the web application security firm Checkmarx
  • The web app library TanStack
  • The enterprise AI platform Mistral AI

Those cascading intrusions let the crew breach the open-source code repository GitHub, data contracting firm Mercor, and employee devices at OpenAI, the European Commission, and many other organizations that public reporting has not named. At times the group deployed a worm called Mini Shai-Hulud, named for the sandworms in Dune, to automate the hacking and reach more victims. The name echoed an earlier Shai-Hulud worm built for a similar approach in September 2025, though it remains unclear whether TeamPCP or any of its alleged members were involved in that earlier campaign.

Google's broader shift toward disruption

Larsen framed the TeamPCP work as part of a change in how Google approaches such cases. The investigation began around the same time as the launch of Google's Cyber Disruption Unit, which has been tasked with a more aggressive posture against cybercrime and state-sponsored hacking.

“Google Threat Intelligence Group has put an emphasis on disruption. That's one of our missions now,” Larsen said. “Writing reports can only be so useful. Taking action to protect users and customers—that is the next step.”

Larsen also said Google received intelligence from ShinyHunters, the partner-turned-rival, and passed identifying details to law enforcement based on what he characterized as operational security mistakes by one of the two Australians now accused of leading the group. Michael Fletcher, a former AFP analyst now working in threat research at an Australian telecom firm, said he approached Larsen around the time the group was ramping up, seeking methods for monitoring its members. Fletcher recalled that Larsen urged caution because one of the hackers was a “friendly.”

“I thought, damn, you all have been inside this early,” Fletcher said.

What this could mean for defenders

The most immediate takeaway for security teams is the mechanics of Google's disruption effort: rather than notifying every breached company one by one — which Larsen said would have taken too long — Google went to the cloud and identity providers where the stolen credentials could be used, and worked to get them revoked. For organizations whose access tokens surface in a supply-chain incident, that routing through providers could be a faster path than case-by-case outreach, though its effectiveness will depend on how quickly providers act and how much of the credential set they can invalidate.

Google's account also suggests that an inside seat in a criminal chat can produce intelligence that external monitoring misses, from the location of a stolen-credential server to the group's internal disputes. That kind of access may not scale — the infiltration depended on months of trust-building with a single actor — and it raises questions about what limits undercover researchers observe, which Larsen addressed only in general terms.

The AI-assisted zero-day is the piece with the widest potential reach. According to Larsen, the exploit was built with an AI tool and worked after minor adjustments, which suggests that AI-assisted development of exploits for unknown flaws is no longer only theoretical. If such work becomes more common, the interval between a vulnerability being found and a working exploit appearing could shrink, which would put more pressure on the patching timelines that defenders already struggle to meet. Google's decision to alert the software's developer and see the flaw patched is one model for handling that; how often similar cases go unnoticed is not something the source material establishes.

#teampcp#supply chain#google#mandiant#shinyhunters#zero-day

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories