An Undercover Google Analyst Spent Time Inside the TeamPCP Supply-Chain Hacking Crew
Ars Technica·medium signal
Google Threat Intelligence Group disclosed it had a mole embedded in the inner circle of TeamPCP, the gang behind a string of software supply-chain compromises. The disclosure is unusual in that Google is describing human infiltration rather than telemetry-based attribution. It follows a run of package-registry attacks where the initial access was social rather than technical, and gives defenders a rare account of how these crews vet and coordinate members.