Authorities arrest 2 alleged members of prolific hacking group TeamPCP

by | Aug 31, 2026 | Technology

Authorities arrest 2 alleged members of prolific hacking group TeamPCP

Law enforcement in Australia announced the arrest of two men on Wednesday in connection with cybercrimes attributed to TeamPCP, a hacking collective responsible for an extensive series of supply-chain attacks. According to the Australian Federal Police, the suspects were charged with 14 offenses and allegedly resided in the Western Australian communities of Cottesloe and Mandurah. Authorities documented that TeamPCP compromised more than 1,000 organizations globally through their coordinated campaign.

TeamPCP emerged in December and became known for a sustained campaign targeting open-source software repositories. The group deployed malware known as Shai-Hulud, which propagated through software supply chains by infecting CI/CD pipelines used in software development and deployment. Once a package or tool became compromised, the worm attached itself to subsequent package updates, spreading infections when developers downloaded and executed the malicious code through their own systems.

The worm’s propagation mechanism relied on a component that extracted credentials stored in infected systems’ memory. Using these stolen credentials, TeamPCP members accessed and compromised additional packages. A notable case involved the Trivy vulnerability scanner compromise, which subsequently led to infections in downstream packages including KICS, the Telnyx Python SDK, and LiteLLM. This initial compromise resulted in the theft of terabytes of sensitive credentials and private information.

Shai-Hulud employed a sophisticated command-and-control infrastructure utilizing Internet Computer Protocol-based smart contracts, which allowed operators to rapidly alter control server URLs and maintain resilience against takedown attempts. Infected systems communicated with the infrastructure at regular intervals. Security researchers noted that TeamPCP members exhibited less operational discipline than typically observed in hacking groups of comparable sophistication, with some analysts attributing this to the accessibility of advanced tools that have reduced technical barriers to entry for cyberattackers.

Australian prosecutors indicated that if convicted, one defendant faces potential imprisonment exceeding 20 years, while the other faces sentencing potentially exceeding 10 years.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI