Google's threat intelligence group infiltrated TeamPCP, a hacker group responsible for unprecedented supply-chain attacks affecting over a thousand companies, through an undercover Mandiant analyst. The infiltration allowed Google to monitor the group's activities, warn breach targets, and assist law enforcement in identifying two arrested Australian members. Google researcher Austin Larsen presented these findings at SentinelOne's LABScon conference.
TanStack supply-chain attack in May 2026 compromised an NPM package repository, leading to unauthorized access of approximately 170 private CrowdSec GitHub repositories by a BreachForum member on May 22nd. CrowdSec discovered and responded to the incident starting September 16th with credential rotation and forensic investigation, finding that while private code was exposed, the primary risk concerned any embedded credentials that required immediate deprecation.