hn.today

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

wired.com16 points0 comments
Screenshot of An undercover Google analyst infiltrated a notorious supply-chain hacking gang

A sophisticated supply-chain hacking ring called TeamPCP conducted an unprecedented campaign that poisoned dozens of open-source projects and cascading toolchains to steal developer credentials and push malware into dependent software. The group compromised projects including the Trivy scanner, LiteLLM, Checkmarx infrastructure, TanStack, and Mistral AI, used a self‑spreading worm dubbed Mini Shai‑Hulud to automate propagation, and ultimately breached repositories and organizations such as GitHub, Mercor, OpenAI, and the European Commission. Despite harvesting roughly half a million credentials, the operation apparently yielded only modest extortion returns, prompting TeamPCP to invite partner groups to monetize the haul.

A long‑running undercover analyst from Google’s security arm (and an earlier Mandiant persona) was embedded in TeamPCP’s inner circle and monitored the CanisterWorm chat, gaining access to stolen credential stores and an AI‑generated zero‑day exploit. The intelligence let Google notify cloud providers like AWS and Microsoft to revoke credentials, alert victims, and help the vulnerable software vendor patch the exploit. Betrayal by partner group ShinyHunters and sloppy operational security - including a trail from forum handles to a Gmail address that was used to back up stolen data to Google Drive - produced actionable leads that were passed to law enforcement and contributed to recent arrests of two alleged TeamPCP members in Australia.

Read on wired.com0 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.