For months TeamPCP looked like an unstoppable machine. The group tainted hundreds of open-source programs with malware, stole developer accounts to keep the chain going and breached more than a thousand companies. According to Google, though, one member of its inner circle was working for the other side almost from the start.
The details came from Austin Larsen, a researcher with the Google Threat Intelligence Group, who described the operation to WIRED ahead of his talk at the LABScon security research conference on September 18, 2026. By then, two alleged leading members of TeamPCP had already been arrested and charged in Australia in late August 2026.
How the cascade worked
TeamPCP, which appears to have surfaced online in late 2025, ran a self-reinforcing loop. It compromised an open-source tool, used the malware to steal developers’ credentials, then planted its code in the next widely used tool. Victims starting in spring 2026 included:
- the open source security scanner Trivy
- the AI API tool LiteLLM
- infrastructure of the security firm Checkmarx
- the web app library TanStack
- the enterprise AI platform Mistral AI
Those footholds led further, to GitHub, the data contracting firm Mercor, employee devices at OpenAI and the European Commission. To scale up, the group sometimes used a self-spreading worm called Mini Shai-Hulud, named after the sandworms in Dune.
A friendly in the chat
Larsen says that in March, just as the spree was getting going, an undercover persona run by Google’s Mandiant was invited into TeamPCP. That persona had spent many months building trust with one of the hackers. It became one of about 12 members of CanisterWorm, the group’s core chat. “So essentially, almost day one, Mandiant was watching everything behind the scenes,” Larsen told WIRED. He stresses that the analyst never took part in any hacking and was “a fly on the wall”.
From the inside, Google reached the server where TeamPCP kept stolen usernames, passwords and access tokens. Instead of alerting every victim one by one, the team first went to the providers where the credentials worked, such as Amazon Web Services and Microsoft, to get them revoked. Hundreds of notification emails followed. The chat also revealed a member using an AI tool to build a zero-day exploit that bypassed two-factor authentication in widely used login software. Google tested the code, confirmed it worked with a few tweaks, and warned the developer, who patched the flaw.
Betrayal and a Google Drive backup
Money was TeamPCP’s weak spot. According to the AFP, the group’s haul included more than half a million users’ credentials, yet Larsen estimates it earned only tens of thousands of dollars from extortion. It brought in partners such as ShinyHunters, who around April began extorting victims without paying TeamPCP its cut. ShinyHunters even sent Larsen an unsolicited log of TeamPCP’s chat. In response, TeamPCP shrank its inner circle and expelled several members, the Google mole among them.
Old-fashioned sleuthing did the rest. A BreachForums data leak linked an active CanisterWorm handle to a Gmail address, and a 2019 forum dispute over pirated Microsoft Office keys tied that address to a PayPal account. When the group’s new credential server turned out to be backed up to a Google Drive on the same account, Google passed the tip to the FBI. Ruben Ian Thomson and Louis Michael Gaebler were later arrested in a joint investigation by Australian police with help from the FBI. Neither could be reached for comment.