Before two alleged members of the notorious TeamPCP hacker group were arrested last month, the group carried out unprecedented supply-chain attacks, compromising hundreds of open-source programs and breaching thousands of companies worldwide. But during a critical moment in the group’s hacking spree, Google's threat intelligence team infiltrated the hackers’ inner circle, allowing the tech giant to monitor and disrupt the attacks from the inside.
The undercover Google analyst was invited to join TeamPCP in March, just as the group was ramping up its campaign. From within, the analyst helped Google warn victims and disrupt the hackers’ attempts to exploit stolen developer accounts. The team sent out hundreds of notifications, preventing potential further breaches.
According to Google Threat Intelligence Group researcher Austin Larsen, the company eventually followed a trail of operational security mistakes made by the alleged TeamPCP members and passed key identifying details to law enforcement. They also received intelligence from another cybercriminal group, ShinyHunters, which had partnered with TeamPCP but later turned against them.
TeamPCP, which appeared online in late 2025, became infamous for its brazen supply-chain attacks, including compromising open-source security tools and infrastructure. The group used a Dune-themed worm to automate its hacking efforts and expand its reach, ultimately breaching major companies and repositories.
Despite the team’s success, Larsen acknowledges that the infiltration was only one part of the broader investigation. 'One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP,' Larsen explained, revealing that Mandiant, Google's security subsidiary, had an undercover analyst within the group from the beginning.







