All incidents

Australian authorities arrest two suspects in TeamPCP supply chain attack case

campaignopenAug 27, 2026 — Aug 27, 2026

AUSTRALIAN police have charged two men in Perth for their alleged role in the TeamPCP supply chain operation that poisoned thousands of open‑source packages used by businesses worldwide, according to the Australian Federal Police. The suspects, aged 21 and 23, are accused of creating malicious code that was inserted into legitimate software projects and then distributed to unsuspecting developers. The operation is described as a global campaign that compromised build pipelines and exposed customer data.

The attackers relied on a self‑propagating worm nicknamed Shai‑Hulud to spread their payloads across repositories, allowing the malicious updates to reach downstream applications without direct interaction. By compromising developer credentials they were able to push tainted builds that appeared benign to automated security checks. Although no CVEs have been published for these specific files, the technique mirrors classic supply chain tactics where trust in open source is abused.

TeamPCP has been linked to a series of intrusions targeting major technology firms, using the same worm to move laterally inside networks after the initial compromise. The group also ran online contests to recruit additional hackers, offering incentives for successful exploitation of the tainted packages. Investigators noted that the leader, known by the alias Ellis, has shown little remorse and has discussed his motivations in previous interviews with security journalists.

KrebsOnSecurity had previously identified one of the suspects in June, highlighting his involvement in the campaign and providing insight into the group's internal dynamics. The recent arrests follow a coordinated effort between the AFP, the FBI and Western Australian Police, demonstrating how international cooperation can disrupt cybercriminal infrastructure that spans continents.

Defenders should treat any unexpected change in a dependency’s behaviour as a potential indicator of compromise, reviewing commit histories and build logs for unfamiliar contributions. Enforcing multi‑factor authentication on developer accounts and limiting privileged access to release pipelines reduces the chance that stolen credentials can be used to push malicious updates.

Maintaining an up‑to‑date software bill of materials for all internal and third‑party code allows teams to quickly spot when a new or altered component appears in a build. Monitoring network traffic for anomalous outbound connections from build servers can help detect the beaconing behaviour associated with worms like Shai‑Hulud.

Finally, sharing indicators of compromise with trusted information‑sharing groups and applying automated policy controls that block executable files from unknown sources adds another layer of defence against similar supply chain threats. Ongoing vigilance and rigorous verification of code provenance remain essential to mitigate the risk posed by groups that abuse the trust inherent in open source ecosystems.

Intelligence briefing updated Aug 27, 2026

TeamPCP
Root sourcewww.afp.gov.au
Timeline Coverage

Swipe to explore timeline