Skip to content

Security1 publisher2 min readPublished

Google put an undercover analyst inside TeamPCP's inner circle during its 1,000-company campaign

TeamPCP hijacked developer accounts, poisoned hundreds of programs and released a worm to automate the spread. Google says the inside access let it warn victims, revoke stolen credentials and help patch an AI-developed zero-day.

The Watch · Security desk

Photograph accompanying Google put an undercover analyst inside TeamPCP's inner circle during its 1,000-company campaign
Photo: scworld.com

What happened

  • Google's threat intelligence group says an undercover researcher was embedded in TeamPCP's inner circle during the group's software supply-chain campaign, based on reporting published by Ars Technica.
  • More than a thousand companies were breached over the course of the campaign.
  • Google used the inside information to warn targeted companies, revoke stolen credentials to disrupt exploitation attempts, and obtain and help patch a zero-day exploit TeamPCP developed using AI.
  • The infiltration also helped law enforcement identify and arrest two alleged key members of the group in Australia.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability Acting on a credential before it is used is a capability no package scanner has; Google could cancel access TeamPCP already held instead of finding malware it had already shipped.
  • constraint A defence built on one embedded human source cannot be bought or repeated on demand, so most organisations only benefit if Google calls them.
  • exposure Anyone who pulled the named tools during the campaign window was reached through their own build pipeline, and the five published names are the only anchors available for a self-check.
  • precedent An AI-developed exploit surfacing through human access to the group that wrote it sets the expectation that intelligence teams see these before defenders do.

Revoking a stolen credential is a different operation from finding a poisoned package, and it comes earlier. Google's researcher was inside TeamPCP's inner circle while the group still held credentials it had stolen, and Google used that position to warn targeted companies and revoke those credentials to disrupt exploitation attempts, according to Ars Technica's account of the disclosure [1][5]. The compromises happened anyway. Hundreds of programs were compromised and more than a thousand companies were breached [2][3].

Credentials are also what the automation ran on. The methods the account attributes to TeamPCP are developer account hijacking and malware distribution through open-source software [2], with a self-spreading worm to automate the attacks [4]. A worm that takes over publishing accounts consumes credentials and produces more of them, so cutting the credential cuts the next hop. Revocation is what Google says it did with the analyst's information [5].

Five names are on the public list: Trivy and LiteLLM among the compromised tools, GitHub, Mercor and OpenAI among the affected entities [6][7]. Against hundreds of compromised programs, those five are a sample [9], and they are what a team checking its own build logs has to work from.

The account is Google's own, relayed by Ars Technica [1]. Google did not give dates for the campaign or the arrests, or name the product affected by the AI-developed zero-day [10].

None of this defence is available for purchase. An organisation cannot buy a seat in an attacker's channel, and the two capabilities that mattered on the victim side were being reachable when Google called and being able to revoke a publishing token quickly [3][5]. The zero-day is the sharper detail: Google obtained an exploit that TeamPCP had developed with AI assistance and helped get it patched before the group used it at scale [5].

What to watch

  • Whether the fuller Ars Technica account lists poisoned package versions and dates, which teams would need to check their own build logs.
  • Charges and court dates for the two people arrested in Australia.
  • Identification of the product targeted by the AI-developed zero-day Google obtained and helped patch.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories