Google Infiltrated Hacking Group TeamPCP
An undercover analyst helped expose a massive credential-theft campaign that compromised over 1,000 global companies.
Updated on Sept. 30, 2026 in Cybersecurity

Live Poll
Do you trust that major technology companies are adequately protecting your data from cyberattacks?
In March 2026, a Google Threat Intelligence Group analyst successfully infiltrated the hacking collective TeamPCP by gaining access to the group’s CanisterWorm communication channel. This operation led to the arrest of two Australian suspects by local police in August 2026.
Why it matters
Google initiated this infiltration to gain visibility into stolen credentials and coordinate bulk revocation, as notifying individual victim organizations had proven ineffective. The operation highlights the scale of security risks inherent in modern software supply chains.
The hacking collective TeamPCP compromised open-source projects such as Trivy and LiteLLM by injecting the automated worm Mini Shai-Hulud. This malware was designed to systematically steal developer credentials from these repositories.
The players
A multinational technology conglomerate operating extensive cloud infrastructure and security research divisions.
TeamPCP
A criminal hacking collective responsible for deploying automated worms to compromise open-source projects.
Ruben Ian Thomson
An Australian citizen arrested in August 2026 for his alleged role in the hacking collective.
Louis Michael Gaebler
An Australian citizen arrested in August 2026 for his alleged role in the hacking collective.
Austin Larsen
A researcher at Google presenting the findings of the infiltration operation at a security conference.
The details
The TeamPCP group utilized the Mini Shai-Hulud worm—a self-propagating piece of code designed to automatically harvest data—to target widely used open-source libraries. By gaining access to the CanisterWorm communications channel, the undercover analyst mapped the scope of the theft and identified compromised accounts. Google coordinated with Microsoft and Amazon Web Services to proactively revoke the stolen credentials before further unauthorized access occurred.
Timeline
March 2026: An undercover analyst began the infiltration of TeamPCP.
August 2026: Australian police arrested two members of the group.
The Tech Race
This intervention highlights the ongoing struggle to secure the software supply chain against automated infiltration tactics. It follows a pattern of heightened activity where security researchers must bypass traditional perimeter defenses to neutralize threats at the source.
Users of open-source projects like Trivy or LiteLLM should monitor security advisories for potential credential rotation requirements. This breach demonstrates why developers must prioritize multi-factor authentication and auditing for all third-party code dependencies.
The takeaway
The successful takedown of TeamPCP underscores the necessity of aggressive, proactive intelligence in preventing supply chain compromises. Organizations should track upcoming security industry conferences where Austin Larsen is scheduled to present the full methodology behind this infiltration.
Further reading
For more on the latest trends in threat intelligence, visit Cybersecurity.
Source note: This article includes information reported by RocketNews.
Live Poll
Do you trust that major technology companies are adequately protecting your data from cyberattacks?







