
Law enforcement in Australia announced the arrest of two individuals charged with participating in cybercrimes connected to TeamPCP, a hacking collective that has executed a sustained campaign of supply-chain attacks. The two men, residents of Western Australian towns, were charged with 14 offenses. According to Australian Federal Police, TeamPCP has compromised more than 1,000 organizations globally through a coordinated series of attacks spanning nine months.
TeamPCP emerged in December and has become known for a particularly sophisticated approach to supply-chain attacks. The group deployed malware known as Shai-Hulud that infected open-source software packages and propagated across development environments. The malware targeted CI/CD pipelines—systems used by developers to rapidly create, update, and distribute software. Once a package was compromised, the malware attached itself to subsequent updates, spreading to any organization that downloaded and deployed the infected versions through their own development infrastructure.
The technical approach relied on a separate component that harvested credentials from infected systems. TeamPCP members used these stolen credentials to compromise additional packages, expanding the scope of infection. In a notable case, the group compromised the Trivy vulnerability scanner, which subsequently infected downstream packages including KICS, the Telnyx Python SDK, and LiteLLM. The initial Trivy compromise resulted in the theft of terabytes of credentials and sensitive data.
The malware incorporated an unusual infrastructure mechanism to protect its command-and-control channels. It utilized a smart contract built on the Internet Computer Protocol, which allowed the worm to locate control servers using URLs that could be rapidly modified. Infected machines communicated with this mechanism approximately every 50 minutes. Security researchers noted that TeamPCP members displayed less operational discipline than typically seen in hacking groups of comparable sophistication, potentially due to the accelerated development capabilities provided by large language models.
Australian authorities indicated that one defendant faces potential imprisonment exceeding 20 years upon conviction, while the other faces more than 10 years if found guilty.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI