Australian Police Arrest Two Suspected TeamPCP Hackers Behind Massive Supply-Chain Campaign

Australian Federal Police announce the arrest of two men accused of participating in cybercrimes for TeamPCP, a prolific hacking group that compromises more than 1,000 organizations worldwide over nine months. The men face 14 charges and live in the Western Australian towns of Cottesloe and Mandurah. While police do not name the defendants, KrebsOnSecurity publishes a lengthy investigation identifying both suspects and detailing the mistakes that lead to their downfall.

TeamPCP emerges in December and quickly vexes law enforcement and security personnel globally with a sustained series of supply-chain attacks. The group's signature malware, a self-propagating worm dubbed Shai-Hulud, laces open source packages with malicious code that spreads from one package to another. The worm targets organizations' CI/CD pipelines, attaching itself to future package updates so that developers who download compromised software unknowingly infect their own systems.

A key component of Shai-Hulud's viral spread harvests credentials for other packages from the memory of infected machines, which TeamPCP members then use to launch new infections. One notable compromise hits the Trivy vulnerability scanner, and the infection cascades downstream to additional packages including KICS, the Telnyx Python SDK, and LiteLLM. The arrests mark a significant breakthrough in efforts to dismantle one of the most aggressive supply-chain attack campaigns in recent memory.

Read More at the original source →