Skip to content
Tech News
← Back to articles

Authorities arrest 2 alleged members of prolific hacking group TeamPCP

read original more articles
Why This Matters

The arrest of two alleged members of the notorious hacking group TeamPCP highlights ongoing efforts to combat sophisticated supply chain attacks that threaten global cybersecurity. This case underscores the importance of strengthening security measures in software development pipelines to prevent widespread malware dissemination. As cybercriminals continue to evolve their tactics, proactive law enforcement actions are crucial for safeguarding organizations and consumers alike.

Key Takeaways

Authorities in Australia said Wednesday that they arrested two men accused of participating in cybercrimes for TeamPCP, a prolific group of hackers that, over nine months, has carried out a relentless series of supply chain attacks that infected more than 1,000 organizations worldwide.

In a statement, the Australian Federal Police said the two men were arrested and charged with 14 offenses. The statement said the men were members of TeamPCP, which by the authorities’ count, compromised more than 1,000 organizations worldwide. The statement didn’t identify the men, except to say they lived in the Western Australian towns of Cottesloe and Mandurah. KrebsOnSecurity, citing a lengthy investigation, provided what it reports to be both defendants’ names, along with an extensive background of their lives and the mistakes that led to their downfall.

The hacks that keep on hacking

TeamPCP has vexed law enforcement officials and security personnel around the world since it emerged in December. The group is best known for a sustained series of supply chain attacks that laced open source software with malware that self-propagated from one package to another. The viral infections worked by targeting organizations’ CI/CD pipelines, which are used to rapidly develop, update, and deploy software.

Once a package or tool was compromised, Shai-Hulud, as the worm was dubbed, attached itself to future package updates. When developers downloaded the compromised packages and ran them through their own CI/CD platforms, their software was also compromised.