Austin Larsen stood before security researchers at LABScon on Sept. 18, 2026, and dropped a revelation. While the loose collective known as TeamPCP tore through open-source repositories and corporate networks earlier this year, Google had eyes inside their most private discussions.
The disclosure, reported first by WIRED, exposed more than just another success for Google’s Threat Intelligence Group. It revealed the rare mechanics of human-source operations against fast-moving cybercrime networks. And it arrived at a moment when supply-chain attacks have become the preferred path for both profit-driven gangs and state-backed operators.
TeamPCP didn’t emerge from a single sophisticated organization. Analysts describe it as a fluid peer community of skilled actors. One clear center of gravity pulled the group together. Its signature move involved stealing developer credentials and secrets from public repositories, then using them to poison popular packages on npm, PyPI, Docker Hub and GitHub.
The damage spread fast. Compromises of tools such as Trivy, KICS, LiteLLM and Telnyx put hundreds of thousands of downstream users at risk. Help Net Security detailed how stolen secrets fueled rapid cloud intrusions. Wiz’s incident response team saw attackers validate credentials, explore environments and exfiltrate data within hours.
But the group’s pace created openings. In March, as TeamPCP launched its most frenzied phase, a Google undercover analyst received an invitation. The analyst joined a core chat called CanisterWorm. Only about a dozen members had access. That access gave Google visibility into stolen credential stores and planned extortion attempts.
“One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group,” Larsen told WIRED ahead of his talk. The analyst wasn’t Larsen himself. Mandiant, Google’s security subsidiary, had cultivated the source well before TeamPCP grabbed headlines.
Google used the vantage point to warn potential victims. In some cases it helped disrupt extortion efforts. The company declined to name the undercover analyst. Operational security demands it. Yet the decision to reveal the infiltration at all signals confidence that the source remains safe and the group has been sufficiently degraded.
TeamPCP’s approach mixed automation with opportunism. Attackers injected malicious code into widely downloaded packages. They created trojanized forks that AI coding assistants would pull in. Some malware samples carried prompt injections designed to defeat security scanners in large language models. The tactic showed criminals adapting to the rise of AI tools faster than many defenders expected.
Recent reporting adds context to the threat environment. On Sept. 17, Google disclosed a separate campaign by China-linked actors targeting software suppliers and SaaS providers. Cybersecurity Dive covered the operation, which used stealthy malware to steal source code and hunt for zero-days. John Hultquist, chief analyst at Google Threat Intelligence Group, called it “a very good intelligence operation” that recalled the SolarWinds breach but with upstream focus on suppliers.
Those state-linked efforts differ from TeamPCP’s financial motives. Yet both highlight the same vulnerability: trust in the software supply chain. Once a developer credential falls, the blast radius can reach thousands of organizations across continents.
Earlier arrests offered partial victories. Australian authorities took two suspected TeamPCP members into custody in August. Brian Krebs reported the development on his site, noting the group’s self-propagating worm Shai-Hulud and its ties to other criminal operations. The arrests did not stop all activity. The collective’s loose structure allows pieces to continue operating.
Google’s inside view delivered immediate value. The analyst gained access to a server holding troves of stolen usernames, passwords and access tokens. Teams could notify affected companies before extortion demands arrived. In at least one instance, the source helped prevent successful data leaks.
Larsen described the operation as a rare alignment of preparation and timing. The Mandiant persona had spent months building rapport with a peripheral actor. When that actor gained entry to TeamPCP’s inner circle, the source followed. Simple in concept. Difficult in practice. Maintaining cover while watching criminal plans unfold tests any operator’s nerve.
The revelation also underscores Google’s evolving role. Once primarily a target of sophisticated espionage, the company now projects power through its threat intelligence arm and Mandiant acquisition. Disruptions of Chinese groups such as UNC2814 earlier in 2026 showed the same pattern: combine intelligence with infrastructure takedowns.
But human sources inside criminal gangs remain exceptional. Most operations rely on technical telemetry, sinkholing domains and law enforcement partnerships. An actual seat at the table changes the equation. It turns defense into something closer to offense.
The Limits of Infiltration
Access brings its own risks. TeamPCP members might detect anomalies. They could feed disinformation back through the source. Google appears to have managed those hazards. The decision to go public suggests the window of value has narrowed or the group has fragmented enough to limit retaliation.
Meanwhile, the broader supply-chain problem grows. North Korean actors compromised the Axios library in March, as Google and others documented. That operation, attributed to UNC1069, installed remote access trojans across platforms. It showed how state programs and criminal gangs sometimes overlap in tactics even if goals differ.
Defenders face a tough asymmetry. Criminals move fast, share tools and adapt code quickly. Companies must protect thousands of dependencies they often don’t fully understand. Google’s success offers a model. Persistent persona cultivation, careful integration into target groups, and rapid translation of intelligence into victim notifications can blunt attacks.
Yet not every organization has Google’s resources. Smaller developers and open-source maintainers remain soft targets. Their compromised credentials become the keys that unlock larger enterprises. The cycle continues.
Larsen’s LABScon presentation laid out the investigation in detail. He avoided sensational claims. The focus stayed on facts: the timing of the invitation, the name of the private chat, the types of data accessed. Those specifics carry weight for practitioners building their own detection strategies.
So what happens next for TeamPCP? The group’s fluid nature suggests fragments will persist. Some actors may reform under new names. Others will sell their stolen credential caches on underground markets. The arrests in Australia and Google’s internal disruption buy time. They don’t solve the underlying weaknesses in how software is built and distributed.
Google’s choice to reveal its undercover operation serves multiple purposes. It warns other criminals that private chats aren’t truly private. It reassures customers that the company acts on intelligence rather than simply publishing reports after the fact. And it reminds the security community that human sources still matter in an age of automated malware and AI-assisted attacks.
The story of the Google analyst inside CanisterWorm will be studied for years. Not because it ended the threat. But because it showed what determined intelligence work can achieve against even the most chaotic adversaries.
Google’s Mole Inside TeamPCP: How an Undercover Analyst Watched a Supply-Chain Rampage Unfold first appeared on Web and IT News.
