As cited
Copy frozen at (site build).
threat intel
Australian cops cuff alleged TeamPCP masterminds
Australian Federal Police arrested two men aged 21 and 23 in Perth on August 28, 2026, identified as the masterminds of TeamPCP, a cybercrime group known for supply chain attacks targeting open-source software repositories. TeamPCP's campaigns injected malicious code into tools like Trivy and created the Shai-Hulud worm targeting npm packages, compromising over 1,000 organizations globally and stealing more than 500,000 credentials plus 300 gigabytes of data. The investigation, conducted with FBI assistance, began in April 2026 after threat assessment companies reported the syndicate's activities; authorities seized electronic devices and data from multiple locations and indicated further arrests are possible.
Why it matters: Open-source developers and organizations relying on npm packages and scanning tools face confirmed exposure from supply chain attacks that harvested credentials and sensitive data; practitioners should review whether their software supply chains included Trivy, npm packages, or other targets of TeamPCP's malicious code insertions.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Australian cops cuff alleged TeamPCP masterminds
Australian Federal Police arrested two men aged 21 and 23 in Perth on August 28, 2026, identified as the masterminds of TeamPCP, a cybercrime group known for supply chain attacks targeting open-source software repositories. TeamPCP's campaigns injected malicious code into tools like Trivy and created the Shai-Hulud worm targeting npm packages, compromising over 1,000 organizations globally and stealing more than 500,000 credentials plus 300 gigabytes of data. The investigation, conducted with FBI assistance, began in April 2026 after threat assessment companies reported the syndicate's activities; authorities seized electronic devices and data from multiple locations and indicated further arrests are possible.
Why it matters: Open-source developers and organizations relying on npm packages and scanning tools face confirmed exposure from supply chain attacks that harvested credentials and sensitive data; practitioners should review whether their software supply chains included Trivy, npm packages, or other targets of TeamPCP's malicious code insertions.
- Source published
- First seen by Cybersecurity Tracker