Australia’s TeamPCP Arrests Expose a Global Software Supply-Chain Threat

Australian authorities have arrested two men accused of taking part in cybercrimes linked to TeamPCP, a hacking group tied to a supply-chain campaign that infected more than 1,000 organizations worldwide. The Australian Federal Police announced the arrests on Wednesday, saying the men had been charged with 14 offenses.
The suspects lived in the Western Australian towns of Cottesloe and Mandurah. If convicted, one faces more than 20 years in prison, while the other faces more than 10 years. Their arrests bring a major international hacking campaign into focus, especially because the group targeted software used by other organizations rather than attacking each victim directly.
How TeamPCP spread its malware
TeamPCP has been active since December and became known for attacks against open source software. The group laced software packages with malware that could spread on its own, turning trusted development tools into a path toward other computers and organizations.
The attacks focused on CI/CD pipelines, the systems organizations use to build, test, and release software. Once attackers compromised one package, the malware could move into future updates. That meant users could receive the malicious code through an update that appeared to come from software they already trusted.
The worm, called Shai-Hulud, attached itself to future package updates after a package or tool had been compromised. Infected packages included Trivy, KICS, the Telnyx Python SDK, and LiteLLM. The initial compromise of Trivy resulted in the theft of terabytes of credentials and private data, giving the attackers access to information far beyond a single infected machine.
The campaign also involved an unusual system for gathering stolen information and locating control servers. Shai-Hulud used an Internet Computer Protocol-based canister to collect credentials and find the servers that controlled the operation. Infected machines checked in with that canister once every 50 minutes.
Two arrests and a group under scrutiny
The arrests followed an investigation that began in April 2026. Information about the defendants and their backgrounds identified Ruben Thomson, also known as Ellis, as one of the alleged hackers. Brian Krebs reported that he had been in contact with Thomson and that Thomson led TeamPCP until March 2026.
The two men are accused of widespread breaches involving the compromise and tampering of popular open source projects. The group’s aim was to infect a large number of computers, steal credentials and data, then pressure victims to pay a ransom.
More than half a million credentials were connected to the campaign’s theft activity, adding to the scale of the operation. The attacks reached organizations through software they used in their own development environments, which made the campaign harder to spot than a direct intrusion against a single company.
That method also explains why the damage spread across so many organizations. A compromised package could reach many users through later updates, allowing one breach to become a much wider infection. For software teams, the case shows how a weak point in an open source project can affect every organization that depends on it.
Investigators also found that TeamPCP members lacked the operational discipline often associated with hackers working at this level. That weakness may have helped authorities connect the activity to the two Australian residents, though the charges still must be tested in court.
The arrests do not erase the exposure created by the compromised packages or the credentials already stolen. They do mark a response to a campaign that turned the software supply chain into an attack route for more than 1,000 organizations.
Based on




