A Hacker Group That Poisoned Open-Source Software at Scale
TeamPCP spent its active years doing something most threat actors only attempt in narrow, targeted ways: systematically poisoning open-source software that developers worldwide pull into their own projects without a second thought. The group tainted hundreds of open-source programs with malware, hijacked developer accounts to keep the contamination spreading, and breached more than a thousand companies before two of its alleged members were arrested and charged in Australia last month.
What made the campaign particularly difficult to contain was its automation. TeamPCP released a self-spreading worm with a Dune theme to accelerate the infection process, turning a manually intensive attack into something that could propagate on its own. The worm handled the grunt work. The humans behind it handled the targeting and the money.

Inside the Group, Before the Arrests
Google’s threat intelligence group has now disclosed that during a key window of TeamPCP’s campaign, a Mandiant analyst – Google’s security subsidiary – was operating undercover inside the group’s inner circle. The analyst was embedded from nearly the start of TeamPCP’s most visible period of activity. That position gave Google a view of the hacking operation from the inside, allowing the company to monitor activity in real time, warn companies that had been breached, and actively help disrupt the group’s attempts to exploit its victims.
The undercover operation will be detailed publicly for the first time at SentinelOne’s LABScon security research conference, where Google Threat Intelligence Group researcher Austin Larsen is presenting the company’s full investigation. Larsen was not the analyst who went undercover – he is the researcher who has been mapping the group’s structure, tracking its mistakes, and building the case that eventually reached law enforcement.
How Google Connected the Dots on Two Australians
Larsen’s path to identifying the alleged ringleaders ran through a series of operational security errors attributed to one of the two Australians now facing charges. The mistakes were small and accumulating – the kind of slip-ups that get ignored in the short term and become fatal to anonymity over time. Google gathered those details and passed them to law enforcement.
The fact that a sophisticated, prolific group could be undone partly by its own carelessness is not unusual in cybercrime investigations. What is unusual is the source network Google was working with to gather intelligence. Among those feeding Google information was ShinyHunters, a separate cybercriminal group with its own well-documented history of large-scale data theft.
ShinyHunters had partnered with TeamPCP at some point during the campaign. The alliance did not hold. ShinyHunters eventually turned on the supply-chain hackers and provided intelligence to Google – a criminal group burning another criminal group, with Google positioned to catch what fell out. The dynamic is uncomfortable but common in threat intelligence work, where information sometimes arrives from sources that are themselves under investigation elsewhere.
That arrangement raises questions about how Google weighed the value of intelligence coming from an active criminal organization against the risk of legitimizing that source through cooperation. Larsen’s LABScon talk is expected to address how the company navigated those relationships during the investigation, though how much detail will be made public remains to be seen.

What Supply-Chain Attacks Mean for the Software You Use
TeamPCP’s method of attack – inserting malware into open-source packages – targets the foundation of how modern software gets built. Developers rely on shared libraries and open-source code to avoid rebuilding common functions from scratch. When those packages are compromised upstream, every application that includes them inherits the infection. The victim count in this campaign, more than a thousand companies, reflects how efficiently that vector scales.
Stealing developer accounts to push malicious updates made the attack harder to detect because the poisoned code appeared to come from trusted, legitimate sources. Package managers and code repositories showed verified contributors pushing updates. Nothing in the chain flagged as anomalous until the malware was already embedded in downstream builds.
The Arrests and What Comes Next
Two Australians accused of being leading members of TeamPCP were arrested and charged last month. The charges follow directly from the trail of identifying information that Google compiled and handed to law enforcement. Whether the arrests represent the full leadership of the group or only part of it has not been publicly confirmed.
Larsen’s presentation at LABScon marks the first time Google has laid out publicly what it knew, when it knew it, and how deeply its operatives were embedded in TeamPCP’s operation. The conference appearance is as much a disclosure as it is a warning – that threat intelligence firms are willing to go further than monitoring when the scale of an attack demands it.

The Dune-themed worm that TeamPCP deployed to automate its spread is still out there in some form, embedded in packages that may not have been fully audited or cleaned. Whether every affected repository has been identified and patched is a question that neither Google nor the arrested developers’ legal teams have fully answered yet.






