Australian police arrest two alleged TeamPCP members over Shai-Hulud software supply-chain attacks

Australian authorities arrested two men they say were part of TeamPCP, a cybercrime group accused of planting malicious code in open-source software used by businesses worldwide. The Australian Federal Police said the suspects, aged 21 and 23, were linked to a campaign that used poisoned npm and GitHub packages and the self-propagating Shai-Hulud worm to steal developer credentials, compromise more packages and repositories, and extort victims. The article ties the group to hundreds of package compromises and follow-on breaches including LiteLLM and GitHub-related incidents.
Why it matters: This matters because TeamPCP’s attacks spread through trusted software components, putting downstream developers and organizations at risk even if they were not the original target. Organizations should review exposure to TeamPCP-linked packages and repos, rotate developer and cloud credentials, and check past alerts tied to Shai-Hulud-style compromises.

Sources

Australian cops cuff alleged TeamPCP masterminds
2026.08.28 99% relevant
This article is another report on the same arrests in Perth of two alleged TeamPCP operators, adding names for the suspects, FBI attribution of one as the alleged leader, and AFP claims that the group's supply-chain attacks compromised more than 1,000 organizations, stole more than 500,000 credentials, and exfiltrated at least 300 GB of data.
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Bill Toulas 2026.08.27 99% relevant
This article is the same underlying event: Australian authorities arresting two alleged TeamPCP members over supply-chain intrusions. It adds detail on the alleged scope of impact, including over 1,000 organizations, roughly 500,000 credentials, at least 300GB of stolen data, the suspects' ages and locations, and the charges announced by AFP, FBI, and Western Australia Police.
Australia charges two men for TeamPCP supply-chain hacking spree
2026.08.27 99% relevant
This is the same underlying event: Australian authorities charging the two alleged TeamPCP members after the arrests, with added details on the 14 charges, the suspects’ identities as reported by ABC, alleged cryptocurrency payments, cooperation with the FBI, and estimates that the campaign compromised 1,000+ organizations, exposed 500,000+ credentials, and caused hundreds of millions in remediation costs.
Australia Arrests 2 Alleged TeamPCP Hackers
Eduard Kovacs 2026.08.27 99% relevant
This is the same underlying event: Australian authorities arrested Ruben Ian Thomson and Louis Michael Gaebler over alleged TeamPCP supply-chain attacks. The article adds detail on the charges, possible prison terms, collaboration with U.S. authorities, alleged targeting of Trivy, KICS, and LiteLLM, use of Mini Shai-Hulud, and police claims of 300 GB exfiltrated from more than 1,000 organizations.
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
info@thehackernews.com (The Hacker News) 2026.08.27 98% relevant
This appears to be the same underlying event, updating the Australian action from arrests to charges against alleged TeamPCP members over the Shai-Hulud supply-chain attacks.
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
BrianKrebs 2026.08.27 100% relevant
This article establishes a distinct law-enforcement story: the arrest of alleged TeamPCP members, which is separate from the individual supply-chain compromises already tracked and adds attribution and disruption details about the broader actor behind them.
← Back to all stories