Concept art of a hooded hacker figure at a laptop with code and a surveillance eye motif representing Google's undercover infiltration of TeamPCP

Google's Undercover Analyst Was Inside TeamPCP as the Supply-Chain Gang Breached 1,000+ Companies

Created on 24 September, 2026IT News • 2 minutes read

Google Threat Intelligence reveals a Mandiant analyst infiltrated TeamPCP, the gang that poisoned hundreds of open-source projects and breached over 1,000 companies.

Google Threat Intelligence Group has disclosed that an undercover Mandiant analyst operated inside TeamPCP's inner circle almost from the beginning of the group's supply-chain hacking campaign, which poisoned hundreds of open-source programs and breached more than 1,000 companies. Google used the access to warn victims, disrupt exploitation, and feed identifying details on alleged members to law enforcement.


An Unprecedented Supply-Chain Rampage


Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. The group's campaign combined several attack techniques into a single, self-reinforcing engine:



  • It tainted hundreds of open-source programs with its malware.

  • It stole developer accounts to perpetuate that software supply-chain hacking.

  • It released a Dune-themed self-spreading worm to automate the process.

  • Ultimately, it breached more than a thousand companies.


Now Google's threat intelligence group has revealed that during a key moment of TeamPCP's rampage, the company's own undercover researcher had infiltrated the group — allowing Google to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group's attempts to exploit those victims.



Inside the Investigation: LABScon and the Larsen Talk


In a talk at security firm SentinelOne's LABScon research conference today, Google Threat Intelligence Group researcher Austin Larsen will present details on the company's investigation — and infiltration — of TeamPCP amidst the group's unprecedented, chaotic supply-chain hacking campaign.


According to Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hacker group and passed on key identifying details to law enforcement.




Google's security subsidiary Mandiant had an undercover analyst — not Larsen himself — within the group's inner circle from almost the beginning of TeamPCP's time in the spotlight.




Intelligence From an Unlikely Source


The company also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with, but which later turned on the supply-chain hackers. That reversal gave Google an additional stream of visibility into the group's operations while its own analyst was already embedded inside.



Why the Infiltration Mattered


The value of human intelligence inside a fast-moving supply-chain campaign is hard to overstate. With a presence in the group's inner circle, Google was positioned to:



  • Monitor the hacking spree from the inside as it unfolded.

  • Warn breach targets before or during exploitation.

  • Help disrupt the group's attempts to exploit those victims.

  • Corroborate identifying details against publicly visible operational security failures.


Perhaps most surprisingly, Larsen says the undercover analyst was not himself — a detail that underscores how long and how deeply the operation ran before it surfaced publicly.



The Takeaway


TeamPCP's campaign shows how a single group can weaponize the open-source ecosystem at scale: stolen developer accounts, poisoned packages, and an automated, self-spreading worm turned a software supply chain into a mass-breach machine. Google's disclosure that it operated from within that machine offers a rare look at how defenders can fight back — not only by detecting and patching, but by gathering intelligence from inside the adversary's own ranks and feeding it to law enforcement.


As the two alleged members in Australia face charges, the full picture of TeamPCP's reach — and of the undercover operation that shadowed it — is only now coming into view.