Two Suspects Arrested in Global Supply Chain Attacks Linked to TeamPCP

www.news4hackers.com-two-suspects-arrested-in-global-supply-chain-attacks-linked-to-teampcp-two-suspects-arrested-in-global-supply-chain-attacks-linked-to-teampcp

Two individuals from Western Australia face charges following allegations of involvement in a global supply chain cyberattack operation attributed to the TeamPCP cybercriminal group.

Arrests and Charges

Australian Federal Police (AFP) arrested a 21-year-old man from Cottesloe and a 23-year-old from Mandurah on August 26 after an investigation revealed their connection to a scheme that injected malicious code into open-source software repositories.

Charges and Penalties

The Cottesloe suspect faces eight charges, including possession and distribution of data for cybercrime purposes, unauthorized data modification, non-compliance with a section 3LA order, and handling proceeds from criminal activities valued at $100,000 or more. Potential penalties for these offenses range from three to 20 years in prison.

The Mandurah suspect was charged with six computer-related crimes, including similar data manipulation and distribution charges, with maximum sentences of five years.

Collaboration and Investigation

The AFP collaborated with the FBI and Western Australia Police Force (WAPF) to execute the arrests. The investigation began in April 2026 after cybersecurity firms identified a syndicate embedding malicious code into open-source projects.

Global Impact of the Attack

Developers unknowingly integrated this code into their applications, leading to widespread infiltration across government, academic, and private sector systems. The malicious software enabled the group to extract sensitive information, including login credentials and authentication tokens.

The AFP reported that the campaign resulted in the theft of over 500,000 credentials and the exfiltration of at least 300 gigabytes of data. Global remediation efforts are estimated to cost hundreds of millions of dollars.

TeamPCP and Malware Tactics

FBI Cyber Division Assistant Director Brett E. Leatherman stated the suspects were allegedly part of TeamPCP, whose activities compromised over 1,000 organizations globally. TeamPCP is linked to supply chain attacks targeting platforms such as GitHub, Telnyx, LiteLLM, Aqua’s Trivy, Checkmarx’s KICS, TanStack, MistralAI, and Red Hat.

Malware and Propagation

The group utilized a self-replicating worm known as Mini Shai-Hulud to steal credentials and propagate malware across software packages. This method was previously associated with the Shai-Hulud worm, which compromised over 180 npm packages in September 2025 by leveraging stolen credentials to spread automatically.

The malware exfiltrated secrets to public GitHub repositories and exposed private repositories.

Expert Analysis and Implications

Aikido Security researcher Charlie Eriksen clarified that TeamPCP was not responsible for the original S1ngularity and Shai-Hulud attacks in 2025 but acknowledged the group’s role in cloning the worm. Eriksen described TeamPCP as a hybrid entity that combined public exploits, research, and malware techniques without exhibiting advanced sophistication.

Threat Landscape

The investigation highlights the evolving tactics of cybercriminal groups, which increasingly mimic organized business models to execute large-scale attacks. The case underscores the vulnerabilities inherent in open-source software ecosystems and the challenges of mitigating supply chain risks.

AFP Commander Graeme Marshall emphasized the growing professionalism of cybercrime networks, noting that investigators are still analyzing seized data and may pursue additional arrests.



About Author

en_USEnglish