Australian authorities have arrested and charged two men suspected of involvement with TeamPCP, a prolific cybercrime group linked to a series of supply chain attacks. Over a nine-month period, the attacks reportedly compromised more than 1,000 organizations worldwide.
In a statement, the Australian Federal Police (AFP) said two people had been arrested and charged with 14 offenses. Investigators allege that both men were members of TeamPCP, which authorities say infiltrated organizations around the world.
The suspects’ identities were not disclosed in the AFP statement. Authorities said they lived in the Western Australian towns of Cottesloe and Mandurah. According to a KrebsOnSecurity report, the arrests followed an extensive investigation that examined the alleged hackers’ backgrounds and the operational mistakes that ultimately led to their identification.
TeamPCP supply chain attacks continue to target software developers
TeamPCP has drawn the attention of law enforcement and cybersecurity researchers since emerging in December. The group is best known for persistent supply chain attacks that compromise open-source software and spread malware from one package to another.
The attacks reportedly target an organization’s CI/CD pipeline, the system used to build, update, test, and deploy software. By compromising a package or development tool, attackers can distribute malware through future updates and connected software environments.
Once a package is infected, the Shai-Hulud worm can be included in subsequent package releases. When developers download the compromised packages and run them through their own CI/CD platforms, the malware can spread into additional applications and organizational systems.
Source: arstechnica.com


