top of page

Australian Authorities Arrest Two Alleged TeamPCP Hackers Behind Global Supply Chain Attacks

Aug 27
3 min read

Key Findings


  • Two Western Australian men, aged 21 and 23, arrested by AFP in connection with TeamPCP, a prolific cybercrime group responsible for the longest running software supply chain attack spree on record

  • Combined 14 charges including unauthorized data modification, possession of data with intent to commit computer offences, and proceeds of crime violations

  • TeamPCP's malicious code potentially compromised over 1,000 organizations globally, stealing more than 500,000 credentials and exfiltrating at least 300 gigabytes of data

  • The group operated by stealing publishing credentials from trusted open-source projects and injecting malicious code into popular software tools used by developers worldwide

  • Group leadership traced to George Prepakis, a security researcher operating under the Twitter/X handle @kernelstub, who created the "Cybercats" Matrix chat server used by multiple cybercrime entities


Background


TeamPCP emerged onto the cybercrime scene in late 2025, quickly establishing itself as a major threat to software supply chains globally. The group represents less a structured criminal organization and more a loosely affiliated community of skilled threat actors who collaborate on shared objectives. What made TeamPCP particularly dangerous was their targeting of the development tools themselves, poisoning the software at its source.


Supply Chain Attack Methods


TeamPCP's core tactic was cyclical and effective. The group gained access to networks where open-source tools were developed, typically through phished or stolen credentials at repositories like GitHub and NPM. Once inside, they embedded malicious code into these tools. When other developers downloaded and used the compromised software, the malware spread to their machines and networks, stealing their credentials in turn. Those stolen credentials granted access to additional open-source projects, allowing the cycle to repeat and their victim network to expand exponentially.


This approach created a cascading compromise. The March 2026 attack on LiteLLM, an open-source AI gateway connecting users to over 100 large language models, demonstrated the scale. The malicious code harvested cloud service keys and secrets from more than 2,500 organizations, including major technology companies. The attack chain showed clear intent: credentials stolen from compromised Trivy scanner code were used to attack Checkmarx KICS days later, which then provided the publishing token used to poison LiteLLM releases.


Recruitment Through Competition


In May 2026, TeamPCP innovated their approach by launching a supply chain hacking contest offering 1,000 Monero in virtual currency to whoever could conduct the largest attack using their Shai-Hulud worm code. Participants were scored based on weekly and monthly downloads of packages they compromised, directly incentivizing targeting the most popular code libraries. Security analysts recognized this as recruitment disguised as competition. TeamPCP later acknowledged the prize was merely a "participation trophy," promising significantly larger payments for meaningful access harvested through the campaigns.


The Arrests and Charges


The 21-year-old suspect faced seven charges including possessing data with intent to commit computer offences, four counts of unauthorized data modification, supplying data with intent to commit computer offence, failing to comply with a compliance order, and dealing with proceeds of crime worth 100,000 or more. The 23-year-old faced six charges covering similar data offences. The proceeds of crime charge carries a maximum 20-year sentence. Search warrants executed at properties in Cottesloe, Hamilton Hill, and Mandurah yielded electronic devices for forensic analysis, though police allege both men received cryptocurrency payments whose full value remains under investigation.


Investigation and Attribution


Private security researchers played a crucial role in identifying the suspects. The 21-year-old's identity was uncovered through leaked password analysis and a decade-old gaming profile that contained identifying information. Communications traced the group back to George Prepakis and the Cybercats Matrix server, where members used Twitter/X handles associated with multiple cybercrime groups that had collaborated on various attacks over nine months.


Analysis by Oligo Security linked TeamPCP infrastructure back to 2020, connecting the group to activity previously tracked as TA-NATALSTATUS and IronErn through overlapping domains, malware deployment paths, and backend infrastructure. Whether this represents a rebrand, shared operator set, or close collaboration between historically related actors remains uncertain.


Impact Assessment


The FBI advised that organizations impacted should treat exfiltrated data and credentials as a persistent risk, since affiliated threat actors are likely to weaponize them long after the initial compromise. Recommendations included rotating all CI/CD secrets, publishing tokens, and cloud credentials that were accessible during exposure windows. Of the organizations potentially compromised, only 16 were confirmed victims on TeamPCP's leak site as of late March, though exposure across CI/CD platforms was widespread. GitLab led affected platforms with 1,064 organizations, followed by GitHub Actions with 618 organizations.


Sources


  • https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/

  • https://thehackernews.com/2026/08/alleged-teampcp-hackers-charged-in.html

  • https://cyberscoop.com/teampcp-cybercrime-arrests-supply-chain-attacks/

  • https://www.securityweek.com/australia-arrests-2-alleged-teampcp-hackers

  • https://www.helpnetsecurity.com/2026/08/27/alleged-teampcp-hackers-arrested-australia

  • https://www.facebook.com/thehackernews/posts/%EF%B8%8F-breaking-two-alleged-teampcp-hackers-charged-in-australiapolice-link-them-to-t/1459167279581184

Recent Posts

See All

Comments


  • Youtube

© 2025 by Explain IT Again. Powered and secured by Wix

bottom of page