Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [CRIME]
2 clusters · 14 sources · 4 days · First seen · Last updated
TeamPCP cybercrime syndicate investigation
Overview
Australian and US authorities have taken action against the TeamPCP cybercrime syndicate, which is accused of conducting large-scale supply chain attacks. The group allegedly utilized the ‘Shai-Hulud worm’ to inject malicious code into open-source software repositories, targeting npm packages and developer credentials.
Two men, aged 21 and 23, were arrested in Western Australia following a joint investigation by the Australian Federal Police, the Western Australia Police Force, and the FBI. The suspects face charges including data intrusion, identity crime, and cryptocurrency-based money laundering. Authorities allege the group targeted specific security tools such as Trivy, Checkmarx KICS, and the AI gateway LiteLLM.
The scale of the breach is significant, with investigators estimating that more than 1,000 organizations globally—including government agencies, academic institutions, and the European Commission—were potentially compromised. The attacks resulted in the theft of approximately 500,000 credentials and the exfiltration of at least 300 gigabytes of data. The FBI has advised impacted organizations to rotate all cloud credentials and CI/CD secrets due to the persistent risk of the stolen data.
Entities
Louis Michael Gaebler · Federal Bureau of Investigation · TeamPCP · Australian Federal Police · Ruben Thomson
Timeline
-
12 days ago
[CRIME] 4 sourcesAustralia charges two men in TeamPCP supply chain cyberattacksTwo Australian men face charges for their alleged roles in the TeamPCP cybercrime group, which conducted global supply chain attacks targeting open-source security tools and compromising thousands of entities.
-
15 days ago
[TECHNOLOGY] 10 sourcesAustralia arrests two men linked to global TeamPCP cybercrime syndicateTwo men in Australia have been charged for their alleged roles in the TeamPCP cybercrime syndicate, which conducted global supply chain attacks compromising over 1,000 organisations and stealing 500,000+ logins
Sources
americanbazaaronline.com · arstechnica.com · connectedtoindia.com · crypto.news · cybernoz.com · dijitaliyidir.com · esecurityplanet.com · flagthis.com · gotira.com · grahamcluley.com · nationalcybersecurity.com · theregister.co.uk · upday.com · zdnet.fr