Australian Authorities Crack Down on TeamPCP Hackers Behind Widespread Supply Chain Attacks
In a major breakthrough, Australian authorities have arrested and charged two young men accused of being part of the notorious hacking group TeamPCP. The group has been linked to a string of far-reaching supply chain attacks that targeted open-source software and developer platforms, compromising sensitive data and credentials from over a thousand organizations worldwide.
TeamPCP’s modus operandi involves injecting malicious code into software hosted on open-source repositories. Developers unknowingly incorporate this tainted code into their own applications, which are then used by government, academic, and private-sector organizations. The group has breached some of the biggest names in tech, including Trivy, LiteLLM, Telnyx, SAP, and TanStack packages. They have also compromised the European Commission, Mistral AI, OpenAI, and GitHub.
The investigation into TeamPCP began in April 2026, after the Australian Federal Police (AFP) and FBI received key information from cybersecurity firms. The two men, aged 21 and 23, were arrested on August 26 in the western Australian cities of Cottesloe and Mandurah. During the law enforcement action, investigators seized electronic devices and other evidence for forensic analysis.
According to the AFP, malicious code distributed by TeamPCP has enabled the theft of half a million credentials and the exfiltration of at least 300GB of data. The financial impact is estimated to be in the hundreds of millions of dollars. “The alleged compromise of a small number of trusted software components had a significant global impact,” reads the AFP announcement.
The two suspects now face a combined 14 charges related to possessing and supplying data for computer offenses and modifying data to facilitate serious crimes. The younger of the two also faces charges for allegedly dealing with at least $100,000 in criminal proceeds and failing to comply with an order requiring access to electronic data.
This arrest marks a significant victory for cybersecurity efforts worldwide. However, experts warn that TeamPCP’s activities may have been carried out by a loose-knit collective of threat actors who all frequent the same hacking forums, Discord servers, and Telegram channels. Further arrests or charges are possible as authorities examine seized evidence.
As this case highlights, supply chain attacks can have devastating consequences for organizations worldwide. It is essential for developers to remain vigilant when incorporating open-source software into their applications. Cybersecurity teams must also stay up-to-date with the latest threats and vulnerabilities to prevent such breaches from occurring in the first place.
In light of this incident, we urge readers to take a closer look at their own supply chains and ensure they are not inadvertently incorporating malicious code into their systems. By doing so, we can all contribute to a safer online environment and mitigate the risk of future attacks.
Source: Bleeping Computer — 2026-08-27