Google said its Mandiant team had an undercover analyst inside TeamPCP for months, giving it near-real-time visibility into the group’s open-source supply-chain campaign even as two alleged members were arrested in Australia. The company says that access let it watch the operation from the inside almost from the start.
Because the persona had already gained the group’s trust, Google could see plans as they formed, warn targeted victims, and help disrupt active exploitation instead of waiting to sort out the damage afterward. The campaign still involved tainted open-source software and stolen developer accounts, but embedded access reduced how far the spree could run.
For defenders, the point is where the value sat: inside the attacker channel, not in after-the-fact infrastructure hunting. If you run threat-intel or incident-response programs that can place humans in active investigations, this is the kind of visibility that can shorten a supply-chain campaign’s useful life.