Two Arrests Put a Number on TeamPCP’s Supply-Chain Damage
Update, 21 September 2026: Google Threat Intelligence has revealed that an undercover Mandiant analyst entered TeamPCP’s core chat near the start of the campaign. The access helped Google warn providers and victims, revoke stolen credentials, disrupt follow-on exploitation and develop evidence later shared with law enforcement. The new reporting and its limits are incorporated below.
Australian authorities have charged two men over their alleged roles in TeamPCP. The arrests are significant, but the numbers disclosed with them matter more: over 1,000 organisations potentially compromised, more than 500,000 credentials stolen, at least 300 GB of data exfiltrated and global remediation costs estimated in the hundreds of millions of dollars.
The Australian Federal Police charged the two Western Australian men with a combined 14 offences. Both are accused of participating in a cybercrime network that inserted malicious code into open-source software, allowing trusted development paths to reach government, academic and private-sector organisations.
The group had an observer inside its core chat
At LABScon, Google Threat Intelligence Group researcher Austin Larsen described how a Mandiant analyst built trust with an actor who was later invited into TeamPCP. The undercover persona entered a core chat called CanisterWorm in March and was one of roughly 12 members with access.
According to Larsen’s account to WIRED, the analyst gained visibility into a server holding usernames, passwords and access tokens stolen from victims. Google contacted providers including Amazon Web Services and Microsoft so credentials could be revoked at the platform level, then sent hundreds of notifications to providers and affected organisations.
This does not mean Google prevented every follow-on compromise or saw every part of TeamPCP. The analyst was later removed when the group narrowed its inner circle. Larsen also said the persona did not conduct illegal hacking or encourage the group’s breaches. The operation depended on observation, notification, provider action and conventional investigation.
A supply-chain campaign can become self-feeding
TeamPCP repeatedly targeted developer accounts, package repositories, CI/CD systems and cloud credentials. One poisoned dependency could expose the access needed to compromise the next project, maintainer or release pipeline. Valid developer authority became a distribution mechanism.
The reported victim and technology set has included Trivy, LiteLLM, TanStack projects, developer infrastructure and systems connected to major technology organisations. Attribution is not equally strong across every named incident, and the charged conduct has not been mapped publicly to every compromise.
The inside access exposed a separate AI-assisted zero-day effort
Google’s visibility also revealed that a member of the core circle was using an AI tool to develop an exploit for a previously unknown flaw in widely used login software. Google obtained the code, tested it, warned the developer and says the flaw was patched. This was separate from the package-poisoning activity and should not be treated as one exploit chain.
The episode matters because it connects intelligence collection directly to prevention. A report published after the campaign can describe what happened. Access during the campaign can help invalidate credentials before the group uses them and move a vulnerable supplier towards a fix.
Two arrests do not close downstream incidents
- Review developer identity events. Investigate token creation, repository access, release activity and CI/CD changes.
- Rotate exposed machine credentials. Prioritise publishing tokens, cloud keys, signing material and automation identities.
- Rebuild affected systems. Revoking an account does not remove persistence from a developer workstation or runner.
- Reconstruct dependency exposure. Identify which versions were fetched, cached, built and released.
- Use provider-level containment. Cloud and source-control providers may be able to invalidate stolen access across many victims faster than individual notifications.
- Preserve attribution boundaries. Treat arrests as allegations and separate confirmed technical evidence from the group’s own claims.
The arrests put names and numbers around the damage. The undercover operation reveals something different: modern supply-chain defence may require watching the campaign while it unfolds and using the visibility to disable trust before the attacker spends it.
Sources
- WIRED, undercover Google analyst inside TeamPCP, published 18 September 2026.
- BlackTree, existing TeamPCP arrest and damage analysis, published 27 August 2026.


