Google Infiltrated Hacking Group TeamPCP

An undercover analyst helped expose a massive credential-theft campaign that compromised over 1,000 global companies.

Updated on Sept. 30, 2026 in Cybersecurity

Bold flat-color editorial illustration of a geometric server rack in navy and cream, evoking cybersecurity risk and digital infrastructure.
Google analysts infiltrated the hacking collective TeamPCP, identifying compromised credentials across 1,000 global companies and leading to two arrests in Australia. AI Illustration. Upload story photo >

Live Poll

Do you trust that major technology companies are adequately protecting your data from cyberattacks?

In March 2026, a Google Threat Intelligence Group analyst successfully infiltrated the hacking collective TeamPCP by gaining access to the group’s CanisterWorm communication channel. This operation led to the arrest of two Australian suspects by local police in August 2026.

Why it matters

Google initiated this infiltration to gain visibility into stolen credentials and coordinate bulk revocation, as notifying individual victim organizations had proven ineffective. The operation highlights the scale of security risks inherent in modern software supply chains.

The hacking collective TeamPCP compromised open-source projects such as Trivy and LiteLLM by injecting the automated worm Mini Shai-Hulud. This malware was designed to systematically steal developer credentials from these repositories.

The players

Google

A multinational technology conglomerate operating extensive cloud infrastructure and security research divisions.

TeamPCP

A criminal hacking collective responsible for deploying automated worms to compromise open-source projects.

Ruben Ian Thomson

An Australian citizen arrested in August 2026 for his alleged role in the hacking collective.

Louis Michael Gaebler

An Australian citizen arrested in August 2026 for his alleged role in the hacking collective.

Austin Larsen

A researcher at Google presenting the findings of the infiltration operation at a security conference.

The details

The TeamPCP group utilized the Mini Shai-Hulud worm—a self-propagating piece of code designed to automatically harvest data—to target widely used open-source libraries. By gaining access to the CanisterWorm communications channel, the undercover analyst mapped the scope of the theft and identified compromised accounts. Google coordinated with Microsoft and Amazon Web Services to proactively revoke the stolen credentials before further unauthorized access occurred.

Timeline

  1. March 2026: An undercover analyst began the infiltration of TeamPCP.

  2. August 2026: Australian police arrested two members of the group.

The Tech Race

This intervention highlights the ongoing struggle to secure the software supply chain against automated infiltration tactics. It follows a pattern of heightened activity where security researchers must bypass traditional perimeter defenses to neutralize threats at the source.

Users of open-source projects like Trivy or LiteLLM should monitor security advisories for potential credential rotation requirements. This breach demonstrates why developers must prioritize multi-factor authentication and auditing for all third-party code dependencies.

The takeaway

The successful takedown of TeamPCP underscores the necessity of aggressive, proactive intelligence in preventing supply chain compromises. Organizations should track upcoming security industry conferences where Austin Larsen is scheduled to present the full methodology behind this infiltration.

Further reading

For more on the latest trends in threat intelligence, visit Cybersecurity.

Source note: This article includes information reported by RocketNews.

Live Poll

Do you trust that major technology companies are adequately protecting your data from cyberattacks?