Before law enforcement ultimately apprehended two of its alleged principal architects in Australia last month, the cybercriminal syndicate known as TeamPCP executed what security experts have described as one of the most audacious and destructive software supply chain hacking sprees in modern computing history. Over a compressed, chaotic operational window, the group successfully compromised hundreds of open-source programs, weaponized stolen developer accounts to perpetuate cascading vulnerabilities, and deployed an automated, Dune-themed self-spreading worm to scale its infrastructure. These concerted efforts ultimately breached more than a thousand corporate entities, technology platforms, and government organizations worldwide.
Yet, unbeknownst to the perpetrators, the operation was monitored from its absolute inception. Google’s elite threat intelligence group revealed that a covert researcher embedded within Mandiant, Google’s premier cybersecurity subsidiary, successfully infiltrated TeamPCP’s inner circle almost from day one. This high-risk undercover operation granted the technology conglomerate unprecedented real-time visibility into the syndicate’s communications, tactical maneuvers, and digital repositories, allowing security teams to issue proactive breach warnings, thwart extortion schemes, and ultimately assist international law enforcement in dismantling the criminal network.
The comprehensive details of this digital espionage and counter-intelligence operation were unveiled by Austin Larsen, a senior researcher with the Google Threat Intelligence Group, during a technical presentation at the LABScon cybersecurity research conference hosted by SentinelOne. According to Larsen, the takedown of TeamPCP was the result of a multi-pronged strategy combining deep-cover human intelligence, traditional digital forensics, betrayal from rival cybercriminal factions, and sloppy operational security (opsec) by the hackers themselves.
Anatomy of an Unprecedented Supply Chain Campaign
The shadowy ecosystem surrounding TeamPCP emerged onto the cybersecurity landscape in late 2025, quickly establishing a reputation for unconventional and aggressive tactics. Rather than relying on traditional perimeter breaches or conventional phishing attacks, the syndicate targeted the foundational infrastructure of modern software development: open-source software repositories and package managers.
By tainting widely used libraries and packages, the group executed a cascading series of supply-chain compromises. When developers downloaded updates for routine programming tools, they inadvertently pulled malicious payloads onto their machines. These payloads subsequently harvested credentials, session tokens, and administrative access rights, which TeamPCP then leveraged to infiltrate downstream corporate networks.
The syndicate’s campaign accelerated dramatically in the spring. Among the early casualties of the spree were several high-profile open-source utilities and enterprise platforms, including the open-source security scanner Trivy, the AI application programming interface management tool LiteLLM, infrastructure belonging to web application security firm Checkmarx, the utility library TanStack, and enterprise AI platform Mistral AI. Each successful compromise served as a springboard, casting a wider net that eventually penetrated the code repository GitHub, data contracting firm Mercor, and internal employee workstations at OpenAI and the European Commission, alongside numerous other undisclosed corporate targets.
To automate and accelerate this expansion, the group occasionally deployed a custom self-spreading worm dubbed "Mini Shai-Hulud"—a clear homage to the gargantuan sandworms of Frank Herbert’s science fiction epic Dune, and a possible nod to an earlier, unrelated intrusion campaign dubbed Shai-Hulud that rattled the developer community in September 2025. This automated propagation allowed TeamPCP to exponentially increase its footprint without requiring continuous manual oversight from its human operators.
Inside the CanisterWorm Inner Circle
The genesis of Google’s visibility into this sprawling campaign dates back to March, when a Mandiant analyst—operating under an established digital persona—successfully cultivated trust with an individual who had received an invitation to join TeamPCP. Following a months-long vetting process, the undercover operative was admitted into the hackers’ core communication channel, a private chat server designated "CanisterWorm."
Out of a collective that eventually grew to roughly a dozen core members, Google’s mole secured a coveted seat at the table. In leaked chat logs presented by security researchers, one boastful TeamPCP member remarked to the group, "You guys should understand that we pulled off the biggest supply chain maybe ever recorded in modern history." Behind the scenes, however, Google was recording every move.

Michael Fletcher, a former analyst with the Australian Federal Police (AFP) who now works in threat research for an Australian telecommunications firm, recalled coordinating with Larsen around the peak of the campaign. When Fletcher inquired about potential methodologies for tracking the group’s movements, Larsen advised him to exercise caution during upcoming engagements because one of the active participants in the threat landscape was already a "friendly." Reflecting on the revelation, Fletcher noted the sheer audacity of having secured an insider vantage point so early in the campaign’s lifecycle.
The undercover operative’s access extended beyond mere communications. The mole successfully penetrated the server where TeamPCP stored its vast trove of stolen credentials—usernames, passwords, and access tokens harvested from hundreds of thousands of developer accounts. Recognizing the imminent danger of widespread extortion and corporate espionage, Larsen and his team initiated a proactive disruption campaign.
"My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen?" Larsen explained in an interview prior to his conference presentation. "Let’s go mess up what they’re doing. That was my goal."
Rather than attempting the arduous and time-consuming process of notifying every individual victim corporation directly, Google opted for a systemic choke point. The threat intelligence team contacted major cloud infrastructure and identity service providers—such as Amazon Web Services and Microsoft—where the stolen credentials were most likely to be weaponized. By immediately invalidating the stolen tokens and forcing password resets across hundreds of enterprise accounts, Google neutralized the immediate utility of the hackers’ data hoard.
Simultaneously, Google’s monitoring of the CanisterWorm chat revealed an alarming secondary development: a core member of the syndicate was utilizing artificial intelligence to develop a zero-day exploit targeting a widely adopted piece of enterprise authentication software. The AI-generated exploit was designed to completely bypass two-factor authentication protocols. Google’s engineering team acquired a sample of the exploit code, tested its efficacy in a controlled environment, and verified that it functioned as intended. The company promptly alerted the affected software vendor, allowing them to patch the vulnerability before it could be weaponized at scale—a rare and documented instance of in-the-wild AI-assisted vulnerability development.
Betrayal, In-Fighting, and Operational Security Failures
As spring turned to summer, TeamPCP faced an internal crisis that would ultimately precipitate its downfall. Despite possessing a database containing credentials for more than half a million users, the syndicate struggled to effectively monetize its haul. According to Australian authorities, while ransomware and extortion groups routinely pull in millions of dollars from similar breaches, TeamPCP’s amateurish monetization strategies yielded only tens of thousands of dollars.
In a desperate bid to scale its profits, the group brought in external partners, offering access to its stolen credential repository in exchange for a percentage of any successful extortion payouts. Among the invited syndicates was ShinyHunters, a prolific cybercriminal collective notorious for high-profile data thefts, including the massive breach of educational software platform Canvas that disrupted thousands of educational institutions across the United States.
The partnership proved short-lived. By April, ShinyHunters turned rogue. Rather than splitting profits, the partner group began conducting independent extortion operations utilizing TeamPCP’s stolen credentials while deliberately withholding the cut owed to the supply-chain hackers. In a dramatic display of cybercriminal infighting, ShinyHunters went so far as to unprompted forward a complete log of TeamPCP’s internal chat server to Google’s researcher, completely unaware that Google already maintained a direct feed via its undercover mole.
ShinyHunters subsequently taunted TeamPCP publicly on social media platform X. Realizing they had been compromised and betrayed, TeamPCP leadership panicked. They abruptly purged their roster, exiling ShinyHunters, several peripheral members, and Google’s undercover analyst from the CanisterWorm chat. "Just delete that and stop sharing shit with shinyhunters," one frustrated TeamPCP leader wrote in a final directive before locking down the channel.
Despite losing direct chat access, the dragnet was already tightening. Traditional digital detective work, combined with catastrophic operational security (opsec) failures by the hackers, provided the final pieces of the puzzle.
Larsen began tracing the digital footprint of the CanisterWorm participants through public leak archives. He discovered that one of the group’s most active handles had previously registered a BreachForums account using the email address [email protected]. Delving deeper into historical forum disputes, Larsen uncovered a 2019 transaction record where the same "sheepstealing" handle engaged in a dispute over pirated Microsoft Office keys, directing refunds to a PayPal account tied explicitly to the email address [email protected].

Concurrently, when TeamPCP migrated its stolen data repository to a new hosting provider following the ShinyHunters betrayal, a trusted intelligence partner alerted Google that the fresh server contents were being actively backed up to a Google Drive account managed by that exact same [email protected] address.
"When we saw that, I just thought: There’s no way. Why would he be sending all of this illicit, stolen material to a Google Drive that’s tied to himself?" Larsen remarked. "That’s when we gave the tip to the FBI."
The Interventions and International Arrests
Federal law enforcement moved swiftly upon receiving the intelligence package. Following standard formal legal processes to secure data warrants, U.S. authorities coordinated with international partners.
In late August, a joint operation executed by the Australian Federal Police (AFP), aided by the Federal Bureau of Investigation (FBI), resulted in the arrest of two Australian men in their early twenties. While local privacy laws initially restricted the formal naming of the suspects in domestic police releases, investigative journalism and subsequent court filings identified them as Ruben Ian Thomson and Louis Michael Gaebler. Thomson was apprehended outside a suburban residence in Western Australia, with footage capturing him being led away by law enforcement in casual loungewear. Both men face severe criminal charges related to computer intrusions, extortion, and participation in a criminal syndicate.
The FBI declined to comment directly on active investigations when contacted by media outlets, but emphasized its ongoing commitment to public-private partnerships as outlined in its updated corporate cyber strategy. The AFP similarly maintained a policy of declining comment on ongoing legal proceedings.
Broader Implications for Cyber Defense
Throughout the investigation, Google emphasized the strict legal and ethical guardrails governing its intelligence operations. Larsen noted that the undercover Mandiant analyst never engaged in illegal hacking, nor did they encourage, facilitate, or assist in any of TeamPCP’s cyberattacks. The operative functioned strictly as an observer—a passive intelligence asset designed to gather actionable defensive data without crossing ethical or legal boundaries.
The proactive posture adopted by Google during the TeamPCP affair signals a broader, strategic evolution within the cybersecurity industry. Historically, threat intelligence groups functioned primarily as descriptive entities, publishing post-mortem reports and advisory whitepapers long after an intrusion had concluded. The establishment of specialized disruption units within major technology conglomerates marks a decisive shift toward active intervention.
"Google Threat Intelligence Group has put an emphasis on disruption. That’s one of our missions now," Larsen concluded. "Writing reports can only be so useful. Taking action to protect users and customers—that is the next step."
As software supply chains continue to grow increasingly complex and interconnected, the TeamPCP case serves as both a cautionary tale regarding the fragility of open-source ecosystems and a blueprint for how aggressive public-private collaboration can neutralize sophisticated modern cyber threats before they achieve total operational dominance.
