
Two Australians, aged 21 and 23, alleged members of TeamPCP, are in custody for orchestrating attacks targeting the software supply chain. Their actions are said to have compromised over 1,000 organizations and stolen more than 500,000 credentials since December 2025.
Arrests in Western Australia
The Australian Federal Police (AFP) arrested two men on August 26, 2026, in Cottesloe and Mandurah, Western Australia. They are accused of being part of TeamPCP, a group responsible for serial attacks on open-source tools such as Trivy, LiteLLM, or Telnyx’s Python SDK. The two suspects, aged 21 and 23, face 14 charges, including unauthorized data modification, possession of data for criminal purposes, and money laundering. The first faces up to 20 years in prison, the second up to 10 years.
A group specializing in supply chain attacks
TeamPCP emerged in late 2025, initially targeting misconfigured cloud infrastructure (Docker APIs, Kubernetes clusters, Redis instances). By 2026, the group shifted to the software supply chain: by infecting a trusted component, it could then contaminate all projects using it. Their method involved injecting malicious code into open-source tools, such as the Trivy vulnerability scanner or the LiteLLM library. Once integrated, this code stole credentials, cloud secrets, or GitHub tokens to pivot to other targets.
The Shai-Hulud worm, used by TeamPCP, spread automatically via CI/CD pipelines (continuous development, testing, and deployment tools). It collected in-memory credentials from infected machines and reused them to compromise other packages. In March 2026, the compromise of Trivy led to the infection of KICS, Telnyx’s Python SDK, and LiteLLM, resulting in the theft of terabytes of data and 500,000 credentials, according to authorities. Other estimates, such as those from CloudSEK, suggest over 2,500 organizations were affected and 434,000 CI/CD pipelines exposed.
Digital traces and a fatal visibility
The investigation, launched in April 2026 following reports from cybersecurity firms, benefited from the excessive visibility of TeamPCP members. Their activity on Telegram, X, Steam (one played Call of Duty), and hacker forums, combined with the reuse of pseudonyms, avatars, or email addresses, allowed authorities to trace them. Raids were conducted in Cottesloe, Hamilton Hill, and Mandurah, with electronic devices seized for analysis.
The group also claimed attacks on entities such as RapidFort (569 GB of data stolen in March 2026), Mercor (4 TB of data exfiltrated), and the European Commission’s cloud infrastructure. TeamPCP collaborated with ransomware groups like VECT 2.0, whose flawed encryption mechanism sometimes destroyed data irreversibly. Indirect victims included organizations like Sportradar, whose data was offered for sale for $50,000.
RecommendedUS allows private cybersecurity firms to hack foreign cybercriminals
What this means for businesses
TeamPCP’s attacks exposed vulnerabilities in supply chain security. In July 2026, the FBI advised treating exfiltrated data and credentials as a persistent risk and systematically renewing CI/CD secrets, GitHub tokens, and cloud access. Global remediation costs are estimated in the hundreds of millions of dollars.
The group also open-sourced the Mini Shai-Hulud framework on GitHub in May 2026, and a new wave of attacks via npm targeted the keyv and cacheable packages in early August. Australian authorities do not rule out further arrests.
These arrests highlight that even the most active groups leave exploitable traces. For businesses, the challenge remains securing access to CI/CD pipelines and monitoring software dependencies. The threat persists: stolen credentials can be reused long after the initial compromises.
Sources
Ars Technica — Two alleged TeamPCP members arrested in Australia
ZATAZ — TeamPCP : deux suspects arrêtés en Australie
TechCrunch — Australian police arrest two over TeamPCP hacks
BleepingComputer — Australia arrests alleged TeamPCP hackers
The Hacker News — Alleged TeamPCP hackers charged in Australia



Comments 0
Sign in to join the discussion.
Be the first to comment.