CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Australian cops cuff alleged TeamPCP masterminds

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5887

As cited

Copy frozen at (site build).

threat intel

Australian cops cuff alleged TeamPCP masterminds

Australian Federal Police arrested two men aged 21 and 23 in Perth on August 28, 2026, identified as the masterminds of TeamPCP, a cybercrime group known for supply chain attacks targeting open-source software repositories. TeamPCP's campaigns injected malicious code into tools like Trivy and created the Shai-Hulud worm targeting npm packages, compromising over 1,000 organizations globally and stealing more than 500,000 credentials plus 300 gigabytes of data. The investigation, conducted with FBI assistance, began in April 2026 after threat assessment companies reported the syndicate's activities; authorities seized electronic devices and data from multiple locations and indicated further arrests are possible.

Why it matters: Open-source developers and organizations relying on npm packages and scanning tools face confirmed exposure from supply chain attacks that harvested credentials and sensitive data; practitioners should review whether their software supply chains included Trivy, npm packages, or other targets of TeamPCP's malicious code insertions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Australian cops cuff alleged TeamPCP masterminds

Australian Federal Police arrested two men aged 21 and 23 in Perth on August 28, 2026, identified as the masterminds of TeamPCP, a cybercrime group known for supply chain attacks targeting open-source software repositories. TeamPCP's campaigns injected malicious code into tools like Trivy and created the Shai-Hulud worm targeting npm packages, compromising over 1,000 organizations globally and stealing more than 500,000 credentials plus 300 gigabytes of data. The investigation, conducted with FBI assistance, began in April 2026 after threat assessment companies reported the syndicate's activities; authorities seized electronic devices and data from multiple locations and indicated further arrests are possible.

Why it matters: Open-source developers and organizations relying on npm packages and scanning tools face confirmed exposure from supply chain attacks that harvested credentials and sensitive data; practitioners should review whether their software supply chains included Trivy, npm packages, or other targets of TeamPCP's malicious code insertions.

VendorsGitHub
Actorsqilin
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary