Main Facts

In the sprawling, often shadowy landscape of modern cybercrime, few campaigns have matched the sheer velocity, chaos, and ambition of the hacker collective known as TeamPCP. Operating with a reckless disregard for digital boundaries, the group carried out what security experts have dubbed the most extensive software supply-chain hacking spree in history. By poisoning hundreds of open-source programs, hijacking developer accounts, and even deploying a Dune-themed self-spreading worm, TeamPCP managed to breach more than a thousand corporate and institutional entities.

Yet, as details revealed by Google’s Threat Intelligence Group highlight, the hackers were fighting a war on multiple fronts—unbeknownst to them, they were being watched from the inside almost from day one.

Following a joint international law enforcement operation spearheaded by the Australian Federal Police (AFP) and the FBI last month, two young Australian men—identified in court and police reports as Ruben Ian Thomson and Louis Michael Gaebler—were arrested and charged with orchestrating the widespread cyberattacks. But the takedown was far from a traditional law enforcement sweep. It was accelerated by a high-stakes intelligence operation that included an undercover Google Mandiant analyst embedded deep within the hackers’ inner circle, a vicious betrayal by a rival cybercriminal gang, and fundamental operational security (opsec) failures that handed investigators the smoking gun.


Chronology of an Unprecedented Hacking Spree

The Ascent and the Dune Worm

TeamPCP emerged onto the digital underground in late 2025, rapidly making headlines for a dizzying string of cascading supply-chain compromises. Instead of targeting single enterprises directly, the group poisoned the very well from which modern software developers draw their tools.

Beginning in the spring, TeamPCP systematically infiltrated major open-source utilities and repositories. Their targets included:

  • The open-source security scanner Trivy
  • The AI application programming interface tool LiteLLM
  • Infrastructure belonging to web application security firm Checkmarx
  • The web app library TanStack
  • The enterprise AI platform Mistral AI

Each successful compromise allowed the group to harvest fresh credentials, cast a wider net, and inject malicious code deeper into the ecosystem. This compounding cycle ultimately allowed them to breach open-source code repository GitHub, data contracting firm Mercor, and employee devices at OpenAI and the European Commission, alongside countless other unnamed organizations.

To automate the expansion of their empire, the group occasionally relied on a self-spreading worm dubbed "Mini Shai-Hulud"—a nod to the giant sandworms of Frank Herbert’s science fiction epic Dune (and a potential reference to an earlier September 2025 intrusion campaign, though ties to TeamPCP remain unverified).

Infiltration: March 2025

Just as TeamPCP’s frenzied campaign was gaining momentum in March, Google’s threat intelligence apparatus scored a massive coup. Months prior, an undercover Google Mandiant analyst had painstakingly cultivated a persona to build trust with an actor slated for invitation into TeamPCP. When that actor was added, the Google operative crossed the threshold into the group’s core chat server, codenamed CanisterWorm.

Out of roughly a dozen members granted access to the inner circle, the Google analyst sat silently as a "fly on the wall," monitoring the group’s chaotic operations, logging stolen credentials, and listening to the hackers boast. As one member wrote in leaked chats retrieved during the operation: "You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history."

Disruptive Action and the AI Zero-Day

Rather than merely observing, Google’s team shifted toward active disruption. Recognizing that alerting hundreds of breached companies individually would be too slow to stop ongoing compromises, Google bypassed the victims and went straight to cloud infrastructure providers like Amazon Web Services (AWS) and Microsoft. By notifying these platforms, Google ensured that stolen credentials were systematically revoked before the hackers could exploit them.

Concurrently, internal chat monitoring revealed a frightening development: a member of TeamPCP was utilizing an artificial intelligence tool to craft a zero-day exploit targeting a widely used login software framework. The goal was to bypass multi-factor authentication (MFA). Google’s elite security analysts managed to acquire a copy of the AI-generated exploit code, test it, and confirm its viability. They quickly warned the software’s developer, who successfully patched the vulnerability before widespread exploitation could occur—a landmark real-world example of AI-assisted vulnerability discovery thwarted by defensive intelligence.


Supporting Data and the Web of Betrayals

Despite sitting atop a colossal trove of more than half a million stolen user credentials, TeamPCP struggled to monetize its haul effectively. While major ransomware cartels rake in millions, TeamPCP’s extortion efforts yielded a paltry tens of thousands of dollars.

Desperate to turn their data into cash, the group invited external cybercriminal syndicates into their circle, offering access to the stolen credentials in exchange for a cut of any successful extortion payments. Among those invited was ShinyHunters, a notorious, long-running hacker collective infamous for high-profile extortions—including the breach of educational software platform Canvas, which paralyzed thousands of US schools.

The Rogue Partner Turns

The partnership was short-lived. Around April, ShinyHunters went rogue. Deciding to cut out the supply-chain hackers entirely, ShinyHunters began executing extortions using TeamPCP’s stolen credentials while keeping 100% of the profits.

An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang

In an extraordinary twist, ShinyHunters actively reached out to Google researcher Austin Larsen, unsolicited, sharing a complete raw log of TeamPCP’s internal chat server—completely unaware that Google already had an operative inside. ShinyHunters also took to social media platform X to mock TeamPCP, frequently referring to them as "SkidPCP"—a derogatory cybercriminal slang term invoking "script kiddies" to diminish their technical prowess.

The public taunting forced TeamPCP into damage control. Realizing there was a leak, the group purged members from the CanisterWorm chat, expelled ShinyHunters, and migrated their stolen data to a brand-new server. Unfortunately for them, the damage was already done.

The Fatal Opsec Blunder

Even after losing their direct inside mole due to the group’s security purge, Google’s team relied on classic, methodical digital detective work. Austin Larsen combed through archival data from the notorious cybercrime forum BreachForums and traced one of the most active chat handles in the CanisterWorm group to a specific Gmail address.

Digging deeper into old forum disputes, Larsen uncovered a 2019 transaction trail involving a user named sheepstealing who demanded a refund from a pirated Microsoft Office seller using a PayPal account tied to the exact same email address.

When TeamPCP migrated their stolen credentials to a new infrastructure host—details of which Google obtained via a trusted security partner—investigators discovered something astonishing: the massive repository of illicitly acquired corporate data was being actively backed up to a Google Drive account linked directly to that same email address.

Faced with such egregious operational security (opsec) failure, Larsen immediately escalated the tip to the FBI. Within minutes, federal law enforcement agents responded, opening the floodgates for formal international warrants.


Official Responses and Law Enforcement Action

Late last month, the international dragnet finally closed. In a coordinated multi-agency operation backed by the FBI, the Australian Federal Police (AFP) executed raids in Western Australia, arresting Ruben Ian Thomson and Louis Michael Gaebler. Because of strict Australian privacy laws, local police press releases omitted their names, but subsequent investigative reporting—including independent work by cyber-sleuth Brian Krebs—aligned with the intelligence provided by Google to confirm their identities.

Video footage released by the AFP showed a 21-year-old suspect being escorted from a suburban home in Hamilton Hill wearing a North Face hoodie and sweatpants.

When approached for comment, the FBI declined to discuss details of an active investigation, though a spokesperson emphasized the agency’s commitment to maximizing disruption against cyber adversaries via international partnerships, as outlined in the newly released FBI Cyber Strategy. The AFP likewise declined to provide further comment.

Google representatives were quick to clarify the strict ethical and legal boundaries maintained throughout the operation. Austin Larsen emphasized that the undercover Mandiant analyst never engaged in illegal hacking, nor did they encourage TeamPCP’s malicious campaigns. "They were a fly on the wall, only saying enough to not be suspicious," Larsen noted. "There are guardrails around what we do."


Implications for the Future of Cybersecurity

The downfall of TeamPCP marks a significant philosophical and operational evolution for the cybersecurity industry at large—and for Google specifically.

Historically, threat intelligence groups have functioned primarily as observers: tracking threat actors, writing retrospective threat reports, and notifying victims after the fact. However, the TeamPCP case study highlights the rising prominence of proactive cyber disruption units. By planting undercover operatives, intercepting zero-day exploits before deployment, proactively revoking credentials with cloud giants like AWS and Microsoft, and feeding actionable intelligence directly to law enforcement, major security vendors are adopting a much more aggressive posture.

As Larsen observed during his presentation at SentinelOne’s LABScon conference: "Google Threat Intelligence Group has put an emphasis on disruption. That’s one of our missions now. Writing reports can only be so useful. Taking action to protect users and customers—that is the next step."

The TeamPCP saga serves as both a cautionary tale for cybercriminals—proving that even the most sophisticated digital anonymity can be undone by poor opsec, internal betrayal, and relentless corporate surveillance—and a blueprint for how the private sector and global law enforcement can successfully dismantle the architects of modern supply-chain chaos.