Australian Police Arrest Two Suspected TeamPCP Supply Chain Hackers

Australian Federal Police announce the arrest of two men from Western Australia, aged 21 and 23, in connection with the cybercrime and data extortion group known as TeamPCP. The group is blamed for the longest running spree of software supply chain attacks ever recorded, embedding malicious code into hundreds of open-source software tools and robbing thousands of businesses globally. Authorities do not officially name the defendants, but KrebsOnSecurity identifies the younger suspect after months of direct communication with him.

TeamPCP emerges in late 2025 and quickly gains notoriety for compromising corporate cloud environments with a self-propagating worm called Shai-Hulud. The worm injects malicious code into open-source programs maintained by developers whose credentials at repositories like GitHub and NPM are phished or stolen. As Wired journalist Andy Greenberg describes, the tactic creates a cycle: malware planted in one developer tool spreads to other developers' machines, steals their credentials, and lets the group publish poisoned versions of even more tools, growing their network of breached systems.

The group also operates a form of cyclical recruitment. After the source code for the third version of Shai-Hulud appears online in May, TeamPCP launches a contest offering $1,000 in virtual currency for the largest supply chain operation using the worm. Contest rules score participants by weekly and monthly download counts of compromised packages, directly incentivizing attacks on the most popular code libraries. Clues left behind by the TeamPCP leader likely contribute to the undoing of the suspects now in custody.

Read More at the original source →