Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Two alleged members of the notorious “TeamPCP” hacking group have been arrested in Australia, marking a significant breakthrough in the global effort to bring down this prolific cybercrime syndicate. The Australian Federal Police (AFP) announced the arrests today, revealing that two men from Western Australia, aged 21 and 23, were taken into custody for their alleged involvement in a “sophisticated cybercrime syndicate” responsible for unleashing devastating software supply chain attacks on thousands of global businesses.

TeamPCP burst onto the cybercrime scene late last year, leaving a trail of destruction as they embedded malicious code in hundreds of open-source software tools. The group’s modus operandi involves exploiting software developers’ credentials at public code repositories like GitHub or NPM, using self-propagating malware dubbed “Shai-Hulud” to compromise corporate cloud environments and steal sensitive data. The cycle repeats, with TeamPCP’s hackers publishing malicious versions of popular software development tools, further compromising the security of global businesses.

According to journalist Andy Greenberg, writing for Wired, TeamPCP’s tactic is a form of cyclical exploitation: “The hackers gain access to a network where an open-source tool commonly used by coders is being developed. They plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders.” This approach has allowed TeamPCP to harvest credentials and publish malicious code with alarming frequency.

What’s particularly concerning about TeamPCP is their practice of cyclical recruitment. In May, they published the source code for Shai-Hulud 3 online, followed by a contest offering $1,000 in virtual currency to participants who could conduct the largest supply chain operation using the worm’s code. The rules incentivized participants to target popular code libraries, directly contributing to the group’s growth and reach.

TeamPCP has also demonstrated a willingness to experiment with new tactics. In March, they compromised the code for LiteLLM, an open-source AI gateway connecting users to 100 large language models. This attack harvested cloud service keys and other secrets from over 2,500 organizations, including top tech companies. Just last month, TeamPCP claimed credit for compromising at least 3,800 GitHub repositories after a developer installed a compromised code extension.

Security experts describe TeamPCP as less of a structured hacking group than an amalgamation of threat actors working together towards similar goals. “It’s not a single operator with a clear structure,” says Austin Larsen, principal threat analyst with the Google Threat Intelligence Group. “It’s a peer community of individually-skilled actors, with one clear center of gravity.”

That center of gravity is reportedly George Prepakis, a security researcher and self-described exploit developer operating under the Twitter handle @kernelstub. His involvement with TeamPCP has raised questions about the lines between cybersecurity research and cybercrime.

The arrests in Australia represent a significant blow to TeamPCP’s operations, but the group’s impact on global businesses will likely be felt for some time to come. As security professionals continue to grapple with the complexities of software supply chain attacks, it’s clear that protecting sensitive data requires an all-hands-on-deck approach – from developers and researchers to law enforcement and policymakers. For individuals and organizations, this means staying vigilant about software updates, using robust authentication practices, and being cautious when interacting with public code repositories. By working together, we can mitigate the damage caused by these sophisticated cybercrime syndicates and keep our digital infrastructure secure.


Source: Krebs on Security — 2026-08-27