Two Australians Charged Over Alleged TeamPCP Software Supply Chain Attacks
Australian authorities have arrested and charged two young men suspected of being involved with TeamPCP, a hacker collective linked to a series of widespread software supply chain attacks.
TeamPCP has targeted open-source software projects and developer platforms over the past year, allegedly stealing credentials, authentication secrets, source code, and other sensitive data.
High-profile incidents attributed to TeamPCP affected Trivy, LiteLLM, Telnyx, SAP, and TanStack packages. The group also allegedly compromised systems associated with the European Commission, Mistral AI, OpenAI, and GitHub.
The attacks involved injecting malicious code into software hosted in open-source repositories. Developers then unknowingly incorporated the compromised code into their own applications, potentially exposing systems used by government agencies, academic institutions, and private companies.
Investigators believe the activity was conducted by a loosely connected network of threat actors who communicated through hacking forums, Discord servers, and Telegram channels, rather than by a single, centrally organized group.
According to the Australian Federal Police (AFP), the FBI, and Western Australia Police, malicious code distributed through TeamPCP attacks could have affected more than 1,000 organizations worldwide. The operation may have resulted in the theft of approximately 500,000 credentials and the exposure of at least 300 GB of data.
“The alleged compromise of a small number of trusted software components had significant global implications.” Read the AFP’s announcement.
“Economic impacts to date include worldwide remediation costs estimated in the hundreds of millions of dollars.”
The investigation began in April 2026 after the AFP and FBI received information from a cybersecurity company.
The suspects, aged 21 and 23, were arrested in the Western Australian cities of Cottesloe and Mandurah on August 26, 2026.

Source: AFP
During the law enforcement operation, investigators seized electronic devices and other evidence for forensic examination.
Police allege that the two suspects received undisclosed cryptocurrency payments for their involvement in TeamPCP’s activities.
Following the arrests, Flare and Brian Krebs published separate reports detailing how Telegram activity, reused aliases, online accounts, and other digital clues allegedly connected TeamPCP members to real-world identities.
The two suspects face a total of 14 charges related to possessing and providing data for the purpose of computer crime, as well as falsifying data in furtherance of a serious crime.
The younger suspect is also charged with handling at least $100,000 in proceeds of crime and failing to comply with orders requiring access to electronic data. The charges carry maximum penalties ranging from three to 20 years in prison per offense.
The AFP said additional arrests and charges could not be ruled out while investigators continue examining the evidence seized during the operation.
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, the effectiveness of your defenses can drop sharply.
Blue Report 2026 measures defense techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




