Post

Two Alleged 'TeamPCP' Hackers Arrested in Australia

Two Alleged 'TeamPCP' Hackers Arrested in Australia

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia 🚨

Authorities in Australia have arrested two men believed to be members of TeamPCP, a notorious cybercrime and data extortion group responsible for a series of software supply chain attacks. The Australian Federal Police (AFP) announced the arrests of two men from Western Australia, aged 21 and 23, in connection with a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.

TeamPCP emerged on the cybercrime scene in late 2025, embedding malicious code in numerous open-source software tools and extorting victims for profit. The group gained notoriety for compromising corporate cloud environments using a self-propagating worm known as Shai-Hulud, which added malicious code to open-source programs maintained by developers whose credentials were phished or stolen.

Journalist Andy Greenberg described TeamPCP’s core tactic as a cyclical exploitation of software developers. The hackers gain access to a network where an open-source tool is being developed, plant malware in the tool, and this malware ends up on other developers’ machines. This allows TeamPCP to steal credentials and publish malicious versions of those tools, perpetuating the cycle.

In May, TeamPCP launched a contest offering $1,000 in virtual currency to participants who could conduct the largest supply chain operation using the worm’s code. The contest was described as a recruitment opportunity, with TeamPCP intending to purchase all meaningful access harvested from participants’ campaigns.

In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM, an open-source AI gateway. An analysis by CloudSEK revealed that this attack harvested cloud service keys and other secrets from over 2,500 organizations. TeamPCP also claimed credit for compromising at least 3,800 code repositories at GitHub.

Security experts suggest that TeamPCP is less of a hacker group and more of a collective of skilled threat actors, with a central figure being George Prepakis, a security researcher who operates the Twitter/X profile @kernelstub. This profile has been used to communicate with other cybercrime entities through a chat server called Cybercats.

For more details, check out the full article: Read full article

This post is licensed under CC BY 4.0 by the author.