Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

TeamPCP hackers arrested in Australia: Inside the supply‑chain crime ring

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-08-30 T 08:32:29 Z | [ 2 MIN READ ]
TeamPCP hackers arrested in Australia: Inside the supply‑chain crime ring
2 Min Read
Share

Australian Federal Police announced on Wednesday that two Western Australian men, aged 21 and 23, were taken into custody in connection with the notorious TeamPCP hackers arrested operation that has poisoned open‑source ecosystems worldwide.

TeamPCP hackers arrested in Australia

The AFP statement describes a “sophisticated cybercrime syndicate” that injected malicious code into popular libraries, stealing credentials and demanding ransom from thousands of firms. Investigators say the arrests mark the first successful takedown of the group’s leadership.

“They are not a state actor, not quite organized crime, and not purely ideological,” said Charlie Eriksen, senior researcher at Aikido Security.

TeamPCP first emerged in late 2025, using a worm dubbed “Shai‑Hulud” to hijack developer accounts on GitHub and NPM. The worm’s code was later turned into a bounty contest that paid ↑ 1,000 Monero for the most compromised packages, effectively crowdsourcing supply‑chain attacks.

In March 2026 the group compromised LiteLLM, an open‑source AI gateway, exfiltrating cloud keys from over ↓ 2,500 organizations, including major tech giants. The following month they claimed responsibility for infiltrating GitHub repositories, affecting roughly 3,800 projects.

Security analysts view the arrests as a watershed moment. Reuters notes that the case reveals how loosely knit hacker collectives can scale attacks with AI‑generated code, a trend that blurs the line between hobbyist and professional threat actors.

The investigation also uncovered links to a Matrix chat room called “Cybercats,” where members of TeamPCP and other groups coordinated. One participant, known online as @pcpcasper, posted videos tied to the Australian neo‑Nazi National Socialist Network, a clue that helped locate the suspects.

While the two detainees await a hearing in Perth Magistrates Court, experts warn that the supply‑chain damage may linger. GitHub has introduced a three‑day “cool‑down” for Dependabot updates, a safeguard accelerated by the Bloomberg report on the attacks.

Authorities continue to trace the group’s financial flows, which were funneled through cryptocurrency wallets and illicit data‑broker sites. The case also highlights how pandemic‑era shifts to remote work expanded the attack surface for supply‑chain threats, a point explored in our recent pandemic coverage.


Intel provided by: Kaelen Frost

Lead Cybersecurity Analyst

Global Data Feed

More from this Intel

Defense-in-Depth AI Security: A Three‑Layer Blueprint for Safeguarding Autonomous Agents

Defense-in-Depth AI Security: A Three‑Layer Blueprint for Safeguarding Autonomous Agents

Aug 29, 2026
Reward Hacking Fuels AI Agents’ Zero‑Day Exploits, Breach of Hugging Face Confirmed by OpenAI

Reward Hacking Fuels AI Agents’ Zero‑Day Exploits, Breach of Hugging...

Aug 28, 2026
GhostJacking Exposed: Why AI Agents Can Propose DNS Changes but Lack Approval Authority

GhostJacking Exposed: Why AI Agents Can Propose DNS Changes but...

Aug 27, 2026
Core Lightning vulnerabilities spark urgent security update

Core Lightning vulnerabilities spark urgent security update

Aug 27, 2026
FBI Shuts Down China‑Linked QTFY Hack Infrastructure Targeting U.S. Data

FBI Shuts Down China‑Linked QTFY Hack Infrastructure Targeting U.S. Data

Aug 27, 2026
EU officials WhatsApp hack reveals coordinated foreign intrusion

EU officials WhatsApp hack reveals coordinated foreign intrusion

Aug 26, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.