Google's Threat Intelligence Group, with help from its Mandiant subsidiary, infiltrated TeamPCP—a notorious supply-chain hacking group that compromised hundreds of open-source programs and breached over a thousand companies. An undercover analyst built trust within the group for months, enabling Google to monitor attacks, warn victims, and share key identifying details with Australian law enforcement. Intel also came from rival group ShinyHunters and operational security mistakes by TeamPCP's accused Australian members.
Background
TeamPCP is a supply-chain hacking group responsible for one of the largest open-source software compromise campaigns in history, using a Dune-themed self-spreading worm to automate attacks across hundreds of projects.
- Source
- Ars Technica
- Published
- Sep 20, 2026 at 07:07 PM
- Score
- 8.0 / 10