Skip to content
Tech News
← Back to articles

Australia arrests alleged TeamPCP hackers behind supply-chain attacks

read original more articles
Why This Matters

The arrest of alleged TeamPCP hackers highlights the ongoing threat of supply-chain attacks in the tech industry, exposing vulnerabilities in open-source software that can have widespread global repercussions. This underscores the importance for organizations and developers to strengthen security measures and monitor third-party code for malicious activity. The incident also demonstrates the increasing sophistication and reach of cybercriminal groups targeting critical infrastructure and digital assets.

Key Takeaways

Australian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks.

TeamPCP is a hacking group known for widespread supply-chain attacks over the past year that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code.

High-profile attacks attributed to TeamPCP have impacted Trivy, LiteLLM, Telnyx, SAP, and TanStack packages, while the group has also breached the European Commission, Mistral AI, OpenAI, and GitHub.

To carry out their attacks, the threat actors injected malicious code into software hosted on open-source repositories, which developers then unknowingly incorporated into their own applications on systems used by government, academic, and private-sector organizations.

Rather than a cohesive group, the malicious activity is believed to have been carried out by a loose-knit collective of threat actors who all frequent the same hacking forums, Discord servers, and Telegram channels.

According to the Australian Federal Police (AFP), the FBI, and Western Australia Police, malicious code distributed by TeamPCP has potentially compromised over a thousand organizations worldwide, enabling the theft of half a million credentials and the exfiltration of at least 300GB of data.

"The alleged compromise of a small number of trusted software components had a significant global impact," reads the AFP announcement.

"To date, the financial impact includes global remediation costs estimated to be hundreds of millions of dollars."

The investigation began in April 2026, after the AFP and FBI received key information from cybersecurity firms.

The two men, aged 21 and 23, were arrested in the western Australian cities of Cottesloe and Mandurah on August 26, 2026.

... continue reading