Google

Austin Larsen

Austin Larsen

2026

The Spice Must Not Flow: Disrupting TeamPCP’s 'Mini Shai-Hulud' Campaign

In May 2026, the financially motivated cybercrime group TeamPCP (UNC6780) launched a massive open-source software supply chain attack that continues to claim victims today. Dubbed "Mini Shai-Hulud," the campaign poisoned GitHub Actions caches across the ecosystem, exploiting vulnerable workflows to harvest high-privilege OIDC tokens directly from runner memory and publish trojanized packages.

But behind their widespread operations is a chaotic ecosystem of fragile egos, hacker drama, betrayals, and operational security failures.

This session covers the Google Threat Intelligence Group's (GTIG) response to the crisis. By coordinating with industry partners and vendors to help mitigate some of the campaign's impact.

While TeamPCP’s operations continue to cause significant damage, this talk details how our coordinated defense frustrated the actors at several critical junctures. We will take attendees behind the scenes of the adversary's operations, exploring how we leveraged OpSec failures and infighting to eventually unmask the real-world identities of key operators.

Attendees will leave with a new understanding of the 'Mini Shai-Hulud' infection chain, the mechanics of provider-level disruption, and the value of exploiting threat actor mistakes and weaknesses. 


About Austin Larsen

Austin Larsen is a Principal Threat Analyst with the Google Threat Intelligence Group (GTIG), where he leads investigations into the most impactful cyber events. From zero-day exploits and supply chain attacks to large-scale extortion operations, he drives coordination between internal teams, industry partners, and law enforcement to investigate, attribute, and disrupt adversaries.

Most recently, he coordinated the investigation into the Axios and TeamPCP cascading supply chain attacks. Previously, he led the investigation into UNC5537, the threat actor behind the Snowflake customer data extortion campaign, an effort critical in protecting hundreds of organizations across the telecommunications, finance, and retail sectors. Earlier at Mandiant, he led the response to UNC4841, a China-nexus campaign targeting Barracuda Email Security Gateways. That work was later cited in the U.S.-China Economic and Security Review Commission's Annual Report to Congress, directly informing national security policy.

Austin's work, spanning major investigations like Snowflake (UNC5537), FreeRadical, members of Scattered Spider (UNC3944), and various nation-state actors, has resulted in criminal arrests, public attributions, and responses from foreign governments. At Mandiant, he also ran the firm's victim notification program in the western United States, coordinating over 1,000 notifications to impacted organizations and briefing U.S. and allied government partners. Beyond these high-impact investigations, he spends time researching emerging cybercriminal groups.