Australian Authorities Arrest Alleged TeamPCP Hackers Behind Global Supply Chain Attacks
Australian law enforcement, in collaboration with the **FBI**, has apprehended two individuals suspected of being part of **TeamPCP**, a hacking group linked to extensive developer supply chain attacks. These attacks compromised open-source software and platforms, leading to the theft of credentials, authentication secrets, and source code from numerous high-profile organizations globally.
Australian authorities have announced the arrest and charging of two young men believed to be members of the **TeamPCP** hacking group. This collective is notorious for a series of far-reaching supply chain attacks targeting open-source software and developer platforms over the past year.
### The Modus Operandi of TeamPCP
**TeamPCP**'s strategy involved injecting malicious code into software hosted on open-source repositories. Developers would then unknowingly integrate this compromised code into their applications, which were subsequently used across government, academic, and private-sector organizations worldwide.
This method allowed the threat actors to steal credentials, authentication secrets, and source code, creating a ripple effect of compromise across the software supply chain.
### High-Profile Victims and Global Impact
Attacks attributed to **TeamPCP** have impacted a wide array of prominent entities and packages, including **Trivy**, **LiteLLM**, **Telnyx**, **SAP**, and **TanStack**. Beyond specific software, the group also reportedly breached the **European Commission**, **Mistral AI**, **OpenAI**, and **GitHub**.
According to the **Australian Federal Police (AFP)**, the malicious code distributed by **TeamPCP** has potentially compromised over a thousand organizations globally, resulting in the theft of half a million credentials and the exfiltration of at least 300GB of data. The **AFP** stated, "The alleged compromise of a small number of trusted software components had a significant global impact," estimating remediation costs in the hundreds of millions of dollars worldwide.
### The Arrests and Ongoing Investigation
The investigation, a joint effort between the **AFP**, **FBI**, and **Western Australia Police**, commenced in April 2026 following crucial intelligence from cybersecurity firms. On August 26, 2026, two men, aged 21 and 23, were arrested in Cottesloe and Mandurah, Western Australia.

Investigators seized electronic devices and other evidence for forensic analysis, alleging that the men received undisclosed cryptocurrency payments for their involvement in **TeamPCP** operations. Following the arrests, cybersecurity firms **Flare** and journalist **Brian Krebs** published independent investigations that detailed how Telegram activity, reused aliases, and online accounts linked alleged **TeamPCP** members to real-world identities.
### Charges and Potential Penalties
The suspects face a combined 14 charges, including possessing and supplying data for computer offenses and modifying data to facilitate serious crimes. The younger individual also faces charges for allegedly dealing with at least $100,000 in criminal proceeds and failing to comply with an order requiring access to electronic data. These charges carry severe penalties, ranging from 3 to 20 years' imprisonment per charge.
The **AFP** has indicated that further arrests or charges have not been ruled out as the examination of seized evidence continues.