hn.today

An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang

wired.com8 points1 comments
Screenshot of An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang

A prolific hacking crew called TeamPCP carried out a cascading software supply-chain campaign that infected hundreds of open-source projects (including Trivy, LiteLLM, Checkmarx infrastructure, TanStack, and Mistral AI), used a self-propagating worm dubbed Mini Shai-Hulud, and ultimately stole hundreds of thousands of credentials to breach more than a thousand companies - targets reportedly included GitHub, Mercor, OpenAI, and the European Commission. Despite the massive haul (Google and law enforcement say the group amassed over half a million user credentials), TeamPCP struggled to monetize the data, taking in only tens of thousands in extortion, and began sharing access with other cybercriminals to squeeze more profit.

Google’s threat intelligence arm and its security unit had an undercover analyst inside TeamPCP’s inner circle almost from the start, gaining access to the group’s core chat and a server holding stolen credentials. With that visibility, Google notified cloud providers like AWS and Microsoft to have compromised credentials revoked, relayed warnings to victims, and provided a patch lead after discovering an AI-assisted zero-day exploit that bypassed two-factor authentication. Operational-security missteps and leaked forum data let investigators link handles to real identities; Google passed identifying details to law enforcement, contributing to arrests in Australia. A partner group, ShinyHunters, also betrayed TeamPCP and supplied additional logs that aided the disruption.

Read on wired.com1 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.