TeamPCP emerged online in late 2025 and built a campaign around repeated software supply-chain compromises. The group infected hundreds of open-source projects, stole developer accounts, and used those accounts to insert malware into additional tools. It also deployed Mini Shai-Hulud, a self-spreading worm named after the sandworms in Dune. The campaign reached more than 1,000 companies.
This spring, the group compromised Trivy, LiteLLM, Checkmarx infrastructure, TanStack, and Mistral AI. The attacks led to breaches involving GitHub, data contractor Mercor, employee devices at OpenAI, the European Commission, and other organizations. Mini Shai-Hulud helped automate the spread. Its name appears to reference a similar worm from September 2025, although TeamPCP’s connection to that earlier operation remains unconfirmed.
Austin Larsen of Google Threat Intelligence Group said at the LABScon security conference on September 18, 2026, that a Mandiant analyst had entered TeamPCP’s inner circle in March. The undercover persona spent months building trust with an actor who joined the group and gained access to a core chat called CanisterWorm. About 12 people belonged to that chat. The analyst also reached a server containing usernames, passwords, and access tokens taken from victims.
Google used that access to disrupt the campaign. The team contacted providers such as Amazon Web Services and Microsoft so they could revoke the credentials, then notified affected organizations. Hundreds of messages went out, and many recipients responded quickly. The group’s internal communications also exposed an AI-assisted zero-day exploit targeting widely used login software. The exploit was designed to bypass two-factor authentication. Google tested the code, confirmed that minor changes made it work, and warned the software developer, who patched the flaw. A Google case study published in May described the exploit but did not identify TeamPCP or explain how Google obtained it.
The Australian Federal Police said the group had collected more than 500,000 user credentials. Its extortion income reached only tens of thousands of dollars, according to Larsen. TeamPCP therefore offered access to other criminal groups, including ShinyHunters, in return for a share of ransom payments. ShinyHunters had previously made millions through data theft and ransomware, including an attack on Canvas that disrupted thousands of US schools. Around April, ShinyHunters used TeamPCP’s credentials for its own extortion and supplied Larsen with a complete chat log. TeamPCP then moved its data, restricted the CanisterWorm chat, and removed ShinyHunters and the Google persona.
Larsen traced one active CanisterWorm handle through a BreachForums data leak to [email protected]. He found a 2019 dispute involving the pseudonym sheepstealing and a seller of pirated Microsoft Office keys, where a refund request pointed to a PayPal account linked to the same address. After TeamPCP changed hosting providers, a trusted partner gave Google information about the new server. The stolen material was being backed up to a Google Drive associated with that account. Google passed the finding to the FBI, which responded within minutes. Brian Krebs had also published separate clues about the same identity.
About a month later, US authorities obtained the account data through a warrant. Australian police then arrested Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early twenties, in a joint investigation supported by the FBI. The AFP described them as principal participants in TeamPCP. Its first public release did not name them because of Australian privacy laws. Neither man responded to requests for comment. Google said its undercover analyst observed the group and did not hack systems or encourage criminal activity.
The investigation began around the launch of Google’s Cyber Disruption Unit. Larsen said Google Threat Intelligence Group now treats direct disruption and user protection as a formal mission alongside reporting.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.