Authorities in Australia have arrested two men believed to be members of TeamPCP, a cybercrime group implicated in a series of software supply chain attacks. The Australian Federal Police (AFP) announced that the suspects, aged 21 and 23, were taken into custody for allegedly creating malicious open-source software that targeted thousands of businesses worldwide. The arrests are part of an ongoing investigation into the group’s activities, which have reportedly caused significant disruptions across various sectors.
According to reporting by KrebsOnSecurity, TeamPCP emerged in late 2025, embedding harmful code into numerous open-source tools and extorting victims for financial gain. The group gained notoriety for using a self-propagating worm named Shai-Hulud to compromise corporate cloud environments, leveraging stolen credentials from developers on platforms like GitHub and NPM.
Operational Tactics and Recruitment
TeamPCP’s operational strategy involves a cyclical exploitation of software developers, as described by journalist Andy Greenberg. The group infiltrates networks where open-source tools are developed, plants malware, and subsequently harvests credentials to publish malicious versions of those tools, thereby expanding their reach.
In a notable recruitment effort, TeamPCP launched a contest offering $1,000 in virtual currency to participants who could execute the largest supply chain operation using the worm’s code. This initiative not only incentivized attacks on popular code libraries but also served as a means to acquire access to compromised systems.
Recent Attacks and Impact
In March 2026, TeamPCP targeted AI infrastructure by compromising the code for LiteLLM, an open-source AI gateway, which resulted in the theft of sensitive cloud service keys from over 2,500 organizations, including major technology firms. Additionally, in May, the group claimed responsibility for breaching approximately 3,800 code repositories on GitHub after a developer unknowingly installed a compromised code extension.
Security experts characterize TeamPCP as a loose coalition of skilled cybercriminals rather than a traditional organized crime group. This decentralized structure allows for flexible collaboration among various actors, complicating efforts to combat their activities.
Next Steps in Legal Proceedings
The two suspects are facing a total of 14 cybercrime charges and are scheduled to appear in Perth Magistrates Court. The AFP has indicated that the investigation is ongoing, with further developments expected as authorities continue to unravel the group’s operations.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



