Google says it placed an undercover analyst inside TeamPCP
Google says one of its threat-intelligence analysts spent months cultivating a false identity and gained access to TeamPCP’s private discussions during the group’s supply-chain hacking campaign. A supply-chain attack turns software trusted by many companies into the entry point: attackers alter a shared open-source package or developer tool, so victims can install malicious code as part of normal updates. Google says the inside access let it see the group’s plans in real time, warn organizations whose systems had been exposed, and help disrupt attempts to use the access it had stolen. The episode matters because TeamPCP’s campaign showed how a compromise of widely used developer software can spread far beyond its original target—and why defenders increasingly need early intelligence, not simply a patch after malicious code is discovered.
