arstechnica.com 20 Sept 2026, 11:07 UTC

Google Infiltrated TeamPCP’s Supply Chain Hackers and Stopped a Zero-Day

Google Infiltrated TeamPCP’s Supply Chain Hackers and Stopped a Zero-Day
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

GOOGLE says one of its Mandiant analysts infiltrated TeamPCP, a hacking group accused of carrying out a large-scale software supply-chain campaign. The group compromised hundreds of open-source projects, stole developers’ credentials and used malware—including the Mini Shai-Hulud worm—to spread to more than 1,000 organisations.

Reported victims included Trivy, LiteLLM, Checkmarx, TanStack, Mistral AI, GitHub, Mercor, OpenAI and the European Commission, although many affected organisations have not been publicly identified.

According to Google Threat Intelligence Group researcher Austin Larsen, the undercover analyst joined a core chat called CanisterWorm in March 2026 and gained access to servers holding usernames, passwords and access tokens stolen from victims. Google sent hundreds of notifications to providers including Amazon Web Services and Microsoft, asking them to revoke the credentials before TeamPCP could use them for extortion.

The analyst also discovered that a member of the group was using an AI tool to create a zero-day exploit targeting widely used login software and bypassing two-factor authentication. Google tested the code, confirmed it worked with modifications, and warned the software developer, who patched the flaw.

Google says more than 500,000 user credentials were collected, while a separate partnership with ShinyHunters later exposed TeamPCP’s internal chats. Investigators linked a prominent TeamPCP handle to Australian Ruben Ian Thomson through leaked forum and payment-account data, and then found stolen material backed up to a Google Drive account associated with him. Google passed the information to the FBI. Thomson and Louis Michael Gaebler were arrested in Australia last month and charged; the allegations have not been tested in court.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline