By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Two Alleged 'TeamPCP' Hackers Arrested in Australia Amidst Supply Chain Attack Probe

Authorities in Australia have apprehended two men, aged 21 and 23, who are believed to be key figures within TeamPCP, a sophisticated cybercrime syndicate notorious for orchestrating what is considered the longest-running spree of software supply chain attacks ever recorded. The Australian Federal Police (AFP), the nation's primary law enforcement agency responsible for federal law and international policing, announced the arrests in Western Australia. These arrests are connected to a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." While the AFP has chosen not to publicly disclose the identities of the arrested individuals, KrebsOnSecurity, a well-respected cybersecurity news outlet founded by Brian Krebs, has independently identified the 21-year-old suspect and has maintained ongoing communication with him since June. This ongoing investigation also incorporates interviews with an individual who has presented themselves as the self-described spokesperson for TeamPCP. Furthermore, the investigation is meticulously examining clues and digital footprints left behind by the alleged leader of TeamPCP, which may have ultimately led to their apprehension.
TeamPCP first gained significant notoriety in the cybersecurity landscape in late 2025. The group rapidly established a reputation for embedding malicious code into a vast array of open-source software tools. Their modus operandi involved extorting victimized businesses for substantial financial gains. The group made considerable headlines for their audacious attacks, particularly their ability to compromise corporate cloud environments. This was often achieved through the deployment of a self-propagating worm, ominously dubbed 'Shai-Hulud.' This worm was designed to inject malicious code into open-source programs. The targets were developers whose credentials, obtained through sophisticated phishing campaigns or outright theft, were compromised on prominent public code repositories such as GitHub, a widely used platform for software development, and NPM, a package registry for JavaScript. Andy Greenberg, a prominent journalist for Wired, a technology magazine known for its coverage of emerging technologies and their impact, described TeamPCP's core tactic as a "cyclical exploitation of software developers." This strategy involved gaining unauthorized access to networks where open-source tools commonly utilized by coders were actively being developed. Once inside, the hackers would plant malware within these development tools. This compromised software would then be distributed to other software developers' machines, including those who were creating other tools intended for use by coders. The embedded malware served a dual purpose: it allowed TeamPCP's hackers to steal credentials, which in turn enabled them to publish malicious versions of these software development tools. This created a self-perpetuating cycle, continuously expanding TeamPCP's network of breached systems and compromised businesses. TeamPCP also employed a strategy that has been described as 'cyclical rec
Original source — read the full reporting at the publisher:
Read on Krebs on SecurityGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.