Authorities arrest 2 alleged members of prolific hacking group TeamPCP
image via Ars Technica
August 28, 2026, 11:15 AM
- •Australian Federal Police said two men from Cottesloe and Mandurah were arrested and charged with 14 offenses tied to TeamPCP.
- •Authorities said TeamPCP compromised more than 1,000 organizations worldwide over a nine-month campaign.
- •The group allegedly used Shai-Hulud, a self-propagating malware worm that spread through compromised software packages and CI/CD pipelines.
- •The malware harvested credentials from memory on infected machines and used them to infect additional software packages.
- •One reported compromise involved the Trivy vulnerability scanner, which then affected downstream packages including KICS, the Telnyx Python SDK, and LiteLLM.
- •KrebsOnSecurity reported that investigators identified the suspects and examined mistakes that allegedly exposed the group’s members.
Australian authorities say they arrested and charged two men alleged to be members of TeamPCP, a hacking group tied to cybercrimes affecting more than 1,000 organizations worldwide. The group is accused of running supply-chain attacks that seeded malware into open source software and spread through developers’ CI/CD pipelines. Its Shai-Hulud worm reportedly stole credentials from infected systems, then used them to compromise additional packages, including a breach chain linked to the Trivy scanner and downstream tools. Australian Federal Police said the suspects face 14 offenses, with potential prison sentences exceeding 20 years for one man and more than 10 years for the other if convicted.
Entities Mentioned
Topics Covered
Comments (0)
No comments yet.