Technology7 min read

Google Took Down TeamPCP: Open-Source Poisoning Gang

Google's undercover analyst secretly infiltrated TeamPCP, the supply chain gang that poisoned hundreds of open-source packages and breached 1,000+ companies.

Google Took Down TeamPCP: Open-Source Poisoning Gang

Key takeaways

  1. 1The Unprecedented Scale of TeamPCP's Hacking Campaign Hundreds of poisoned open-source packages.
  2. 2The 2020 SolarWinds compromise illustrated this devastation in a government context — a single poisoned software update reached approximately 18,000 customers, including multiple U.
  3. 3The 2021 Codecov breach showed that even developer tooling, the infrastructure that builds software, could become a vector for credential theft at scale.
  4. 4Google's Covert Infiltration of TeamPCP Infiltrating a cybercriminal gang is not a standard item in a threat intelligence team's playbook.
Sections · 5

When security researchers talk about supply chain attacks, they usually speak in hypotheticals — the theoretical danger of a malicious package slipping into a developer's dependency tree. TeamPCP made that hypothetical real, at industrial scale. Before two of its alleged members were arrested in Australia, this group had poisoned hundreds of open-source packages, compromised more than a thousand companies worldwide, and automated its own chaos with a self-spreading worm inspired by Dune. What they didn't know was that Google had been watching from the inside.

At SentinelOne's LABScon 2026 security research conference, Google Threat Intelligence Group researcher Austin Larsen revealed that his team had placed an undercover analyst inside TeamPCP during a critical phase of the group's campaign — allowing Google to monitor the operation in real time, warn compromised organizations, and actively work to blunt the damage. It is one of the most consequential covert infiltrations of a cybercriminal threat actor in recent memory.

The Unprecedented Scale of TeamPCP's Hacking Campaign

Hundreds of poisoned open-source packages. More than one thousand breached companies. A self-propagating worm built to automate infection. These figures frame the TeamPCP supply chain attack not as a clever proof-of-concept but as one of the most disruptive software supply chain campaigns ever recorded.

Software supply chain attacks are particularly dangerous because they exploit trust. Developers trust the packages they install. Enterprises trust the software their developers build. When a package is compromised at the source, that trust cascades into every downstream environment. The 2020 SolarWinds compromise illustrated this devastation in a government context — a single poisoned software update reached approximately 18,000 customers, including multiple U.S. federal agencies. The 2021 Codecov breach showed that even developer tooling, the infrastructure that builds software, could become a vector for credential theft at scale.

TeamPCP appears to have taken both lessons and industrialized them. Rather than targeting a single vendor's update mechanism, the group went after the open-source ecosystem itself — the fragmented, community-maintained substrate on which virtually every modern software project depends. By compromising hundreds of packages, TeamPCP didn't need a single high-value target. It had an entire supply chain as its attack surface.

The group also stole developer account credentials to perpetuate its reach, publishing malicious code under the names and reputations of legitimate maintainers. Victims had no reason to distrust software signed by a recognized developer. That's the particular cruelty of account-hijacking within a supply chain attack: it weaponizes community trust itself.

Google's Covert Infiltration of TeamPCP

Infiltrating a cybercriminal gang is not a standard item in a threat intelligence team's playbook. Passive monitoring, indicator sharing, and reverse engineering of malware samples are the bread and butter of this work. Active human infiltration — placing a researcher inside a group to observe communications and operations in real time — is rare, legally complex, and operationally demanding.

Read next Laika's Wildwood: Stop-Motion Fantasy at TIFF 2026

According to Larsen's presentation at LABScon 2026, a Google Threat Intelligence Group researcher operating undercover managed to gain access to TeamPCP's internal operations during a key moment in the group's hacking spree. What that enabled was qualitatively different from external monitoring. Google could see not just the artifacts of an attack after the fact, but the group's intentions, targets, and tactics as they developed.

That visibility had direct, practical consequences for the victims. Google used the intelligence gathered through the infiltration to warn organizations that had been breached or were about to be targeted — giving defenders actionable information in near-real time rather than weeks or months after the fact. The company also worked to disrupt TeamPCP's attempts to exploit compromised victims, placing friction in the path of a group that had, until that point, operated with considerable impunity.

The decision to send a researcher undercover rather than simply sharing indicators with law enforcement reflects both the urgency of the situation and the limitations of traditional intelligence pipelines. When a group is actively poisoning packages at speed and breaching companies in bulk, the window for intervention is short. Covert access compressed that window.

Operational Security Mistakes That Unmasked the Group

Every successful investigation of an anonymous threat actor eventually traces back to a mistake — a moment when the operational discipline that kept someone hidden slipped. TeamPCP was no exception.

Larsen disclosed that Google eventually followed a trail of operational security failures attributed to one of the two Australians now facing charges. The nature of those specific failures was not detailed in the reported summary, but the pattern is familiar to anyone who has studied how cybercriminal groups are eventually identified. Persistent actors make persistent mistakes. A reused username, an account created before anonymization tools were in place, an IP address logged at an inopportune moment — any of these can unravel years of careful concealment.

What distinguishes this case is that the operational security lapses didn't just surface in retrospect. Google's undercover presence meant that the investigation had context — a structured understanding of the group's membership, hierarchy, and communications — against which those mistakes could be interpreted and attributed. Anomalies that might have looked like noise in a purely external investigation became meaningful signals when viewed from the inside.

This is the compounding value of covert infiltration: it doesn't just generate intelligence about what a group is doing. It generates the interpretive framework needed to understand what the evidence means.

The Arrests and Charges Against the Australian Members

Two individuals alleged to be members of TeamPCP were arrested and charged in Australia in the weeks before Google's public disclosure at LABScon. Larsen's presentation represents the first time the full scope of Google's involvement — including the infiltration — has been described publicly.

The charges in Australia mark a concrete legal endpoint to a campaign that had, for its operational period, proceeded without meaningful accountability. Supply chain hacking groups frequently operate across jurisdictions, exploiting the coordination challenges between national law enforcement agencies. The arrests suggest that the trail of evidence assembled — through both conventional investigative means and Google's internal access — was sufficient to satisfy the evidentiary standards of a criminal prosecution.

It is worth noting what these arrests represent structurally. Most supply chain attack campaigns do not end with named individuals facing criminal charges. Groups dissolve, rebrand, or simply stop, leaving no accountability trail. The Australian arrests place TeamPCP in a much smaller category of threat actors that law enforcement was able to identify, locate, and charge. That outcome was not accidental. It required intelligence work precise enough to link specific individuals to specific acts — the kind of precision that inside access materially enables.

What This Means for Open-Source and Supply Chain Security

The TeamPCP supply chain attack, and the investigation that dismantled it, carries several implications for the software industry and the security community.

First, the scale of the campaign confirms that the open-source ecosystem remains a high-value, insufficiently defended attack surface. Package registries have made progress on security controls — multi-factor authentication requirements, provenance attestation, automated malware scanning — but hundreds of poisoned packages reaching production environments demonstrates that those controls are not yet comprehensive. Every organization that builds software on open-source dependencies should treat supply chain integrity as a primary security concern, not an afterthought.

Second, account compromise is the entry point that makes ecosystem-level attacks possible. TeamPCP's use of stolen developer credentials to publish malicious packages underscores the need for hardware security keys and phishing-resistant authentication across package registry accounts. A developer's PyPI or npm credentials are not just personal assets. They are trust certificates for the entire downstream community that uses their software.

Third, the Google infiltration establishes a model — and raises questions — about the role private threat intelligence firms can and should play in active disruption operations. Google's ability to warn breach victims in real time prevented harm that law enforcement, operating on longer timelines, could not have prevented. That's a genuine public good. It also represents a form of private intelligence action that operates largely outside public accountability frameworks.

Finally, the Dune-themed worm deserves more than passing mention. The decision to build a self-spreading, automated infection mechanism signals that TeamPCP was not improvising. This was a group with engineering discipline and an ambition to scale. That ambition, combined with the inherent openness of the software supply chain, is what made the campaign so damaging. It is also what makes the inside infiltration and eventual disruption so significant — because against a group operating at that level of automation, passive defense was never going to be enough.


Source: Ars Technica - All content

Published

28 September 2026

Author

Editorial

Comments

No comments yet. Be the first.

Leave a comment