https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia

Australian Federal Police have arrested two men from Western Australia, aged 21 and 23, in connection with TeamPCP, a cybercrime and data extortion group described as responsible for the longest running spree of software supply chain attacks ever recorded. The AFP characterised the group as a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses. KrebsOnSecurity reported that it had independently identified the 21-year-old suspect in June and had been in communication with him since, with the story including interviews with TeamPCP’s self-described spokesperson and an examination of the operational security failures that likely led to the arrests.

TeamPCP emerged in late 2025 and built its operation around embedding malicious code in hundreds of open source software tools, then extorting victims for profit. Its core mechanism was a self-propagating worm called Shai-Hulud, which added malicious code to open source programs maintained by developers whose credentials at public repositories including GitHub and NPM had been phished or stolen. The cyclical nature of the attack meant that compromised developer machines became vectors for further compromise, as malware planted in tools used by coders spread to other tools being developed by those same coders, allowing TeamPCP to continuously expand the collection of breached networks and credentials available to it.

The two suspects now face a a combined of 14 charges related to possessing and supplying data for computer offenses and modifying data to facilitate serious crimes.

Discover more from Edwin Kwan

Subscribe now to keep reading and get access to the full archive.

Continue reading