Authorities arrest 2 alleged members of prolific hacking group TeamPCP

by | Sep 8, 2026 | Technology

Authorities arrest 2 alleged members of prolific hacking group TeamPCP

Law enforcement in Australia announced the arrest of two men charged with 14 cybercrimes related to their alleged membership in TeamPCP, a hacking collective that has conducted widespread supply-chain attacks targeting organizations globally. The suspects, identified by their residences in Western Australian towns, are accused of participating in the group’s operations that compromised more than 1,000 organizations over a nine-month period.

TeamPCP gained notoriety for its sustained campaigns targeting open source software through a sophisticated worm known as Shai-Hulud. The malware was engineered to self-propagate across software development pipelines by targeting CI/CD systems used by organizations to develop, test, and deploy software updates. Once a package or tool became infected, the worm attached itself to subsequent package updates, spreading infections downstream when developers incorporated the compromised components into their own systems.

The worm’s propagation mechanism relied on a separate component designed to harvest credentials stored in the memory of infected machines. Using these stolen credentials, TeamPCP members gained access to additional packages and infrastructure to expand the scope of their attacks. A notable case involved the compromise of the Trivy vulnerability scanner, which subsequently infected multiple downstream packages including KICS, the Telnyx Python SDK, and LiteLLM, resulting in the theft of terabytes of credentials and sensitive data.

Shai-Hulud employed an unconventional infrastructure based on Internet Computer Protocol smart contracts to maintain resilient command-and-control channels. This approach allowed the malware to identify control servers using dynamically changeable URLs, with infected machines reporting back to the system at regular intervals.

Security researchers noted that TeamPCP members demonstrated less operational sophistication than typical hacking groups of comparable accomplishment, with some analysts attributing this to the increased accessibility of advanced techniques through large language models. Australian authorities indicated that conviction could result in sentences exceeding 20 years for one defendant and more than 10 years for the other.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI