Google infiltrates TeamPCP, disrupts attacks on 1,000 firms
Google’s Mandiant subsidiary infiltrated TeamPCP’s private CanisterWorm chat in March 2026, giving the company an inside view of the group’s sweeping software supply-chain campaign. TeamPCP compromised hundreds of open-source packages, stole developer credentials and used a self-spreading worm to breach more than 1,000 organizations, including major companies and government-related targets. Google used the intelligence to warn victims, help disrupt follow-on attacks and provide identifying information to law enforcement; two alleged Australian members later faced arrest and charges. The campaign reportedly exposed more than 500,000 credentials and at least 300 gigabytes of data, while highlighting the growing threat posed by attacks on widely used software dependencies.






