Australia Arrests Two Men Allegedly Linked to TeamPCP Cybercrime Network

Australian authorities have arrested two men accused of belonging to TeamPCP, a cybercrime network linked to a series of software supply-chain compromises and data-extortion campaigns affecting organi...

Australian authorities have arrested two men accused of belonging to TeamPCP, a cybercrime network linked to a series of software supply-chain compromises and data-extortion campaigns affecting organizations worldwide.

The Australian Federal Police said the suspects, aged 21 and 23 and both from Western Australia, were detained in connection with an alleged syndicate that created and distributed malicious open-source software. Investigators have not publicly identified either man, and the allegations have not been tested in court.

TeamPCP emerged prominently in late 2025 after attackers used compromised developer accounts and poisoned software packages to spread malware. One of the group’s tools, the self-propagating Shai-Hulud worm, was designed to steal credentials and cloud secrets from software developers and use them to compromise additional projects. The resulting cycle enabled malicious code to move through widely used development ecosystems.

Security researchers have also associated the group with an attack on LiteLLM, an open-source gateway for large-language-model services. CloudSEK reported that the campaign exposed credentials and other secrets belonging to more than 2,500 organizations. TeamPCP later claimed that one operation had affected thousands of repositories hosted on GitHub.

A loose criminal alliance

Threat intelligence analysts describe TeamPCP less as a conventional gang than as a network of independent actors who collaborate around common objectives. The group has reportedly used online communities to recruit participants, including a contest that offered cryptocurrency rewards for compromising software packages with large download volumes.

Investigative reporting has linked several aliases in the group’s communications to other extortion and data-broker operations. One suspected participant, known online as “pcpcasper,” has been associated with Western Australia and was identified by a source as one of the arrested individuals. That attribution has not been confirmed by Australian authorities.

The arrests follow months of activity involving stolen credentials, malicious package releases and alleged access sales. The case illustrates how attackers can exploit trust in open-source software to reach large numbers of downstream organizations, while investigators continue working to determine the full scope of the network and its alleged crimes.