Urgent.News

What's breaking now, across thousands of outlets.

Tech

An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang

TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.

An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang

Google's threat intelligence team has revealed a significant infiltration of the notorious supply-chain hacking gang TeamPCP. Austin Larsen, a researcher at Google's Threat Intelligence Group, presented details of their investigation and infiltration at the LABScon security research conference. The group, which began appearing online in late 2025, had launched a series of supply-chain attacks, compromising open-source software and hijacking the credentials of software developers.

This allowed the group to repeatedly exploit victims and breach high-profile targets, including Github, Mercor, and employee devices at OpenAI, the European Commission, and unnamed others.

According to Larsen, Google's undercover researcher was invited to join TeamPCP's inner circle almost from the group's inception. This mole, one of about 12 members given access to a core chat called CanisterWorm, provided Google with valuable insights into the hackers' activities. The researcher gained access to a server storing stolen credentials, which Google used to warn victims and prevent the ransom scheme.

Instead of directly alerting the breached companies, Google targeted providers like Amazon Web Services and Microsoft to revoke the compromised credentials.

In addition, Google's team discovered that someone within TeamPCP's inner circle was developing a zero-day exploit in widely used login software. Google tested the exploit code and found it to be effective, marking a rare instance of an in-the-wild AI-created hacking technique.

Written by urgent.news from Wired's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at wired.com →

More in Tech

More from Friday 18 September →