Google had a mole inside history's wildest supply-chain hack gang

An undercover Google analyst spent months inside a notorious hacker group's private chat, watching a massive supply-chain attack unfold in real time.
Google Threat Intelligence revealed that a Mandiant analyst secretly infiltrated TeamPCP, the group behind a chaotic string of supply-chain breaches. TeamPCP hijacked popular open-source tools—including LiteLLM, TanStack, and Trivy—stole developer logins, and breached over 1,000 targets, including OpenAI, GitHub, and the European Commission. They even deployed a Dune-themed self-spreading worm named Mini Shai-Hulud to automate the fallout.
Because Google had a mole inside the group's 12-person inner chat almost from day one, researchers gained access to the hackers' stash of stolen credentials. Google tipped off cloud providers like AWS and Microsoft to revoke keys before the hackers could extort victims, and passed operational security slips to law enforcement, leading to two arrests in Australia.
Why it matters: Supply-chain attacks usually leave security teams blind until the damage is done. By embedding a persona directly in the hackers' inner circle, Google turned an active crime spree into a live monitoring operation, quietly cutting off access before the hackers could cash in.
Know this: Open-source supply chains remain a soft target. Taint one popular library, and you can harvest credentials across thousands of downstream corporate networks in hours.
Note to cybercriminals: double-check who's lurking in your private group chats.
Sources
- An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang — https://arstechnica.com/security/2026/09/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/

