Police have charged two men from Western Australia over their alleged involvement in TeamPCP, a cybercriminal gang that has been blamed for a massive software supply-chain hacking campaign. TeamPCP is best known for Shai-Hulud, a self-propagating worm that spread itself through open source software.
The Australian Federal Police (AFP), working with the FBI and Western Australia Police, announced that on 26 August they charged a 21-year-old from Cottesloe and a 23-year-old from Mandurah with multiple offences, including data intrusion and unauthorised modification of data. Both men appeared in court in Perth on Thursday.
According to the authorities, the two men were principal members of a "sophisticated cybercrime syndicate" that created malicious open source software designed to steal data and extort ransoms from businesses. More than 1000 organisations around the world are estimated to have been compromised in the attacks, with over 500,000 credentials and at least 300GB of data stolen.
Neither of the men has been formally named by the police, but cybercrime investigative journalist Brian Krebs reports that the 21-year-old is Ruben Thomson, who used the handle "Ellis" and allegedly led TeamPCP until March 2026.
First emerging in late 2025, TeamPCP built a reputation for poisoning popular open source packages rather than directly attacking businesses. By compromising individual pieces of widely-used software their attack could impact thousands of victims at once.
The group's Shai-Hulud worm hijacks GitHub and NPM developer credentials, and publishes boobytrapped versions of legitimate software packages. Anyone who uses the package in their own software risks sharing their own secret API keys and credentials with the hackers, opening the door for a further round of compromises.
Hacks linked to TeamPCP include the compromise of vulnerability scanner Trivy, which led to the breaches of open source AI gateway LiteLLM, and AI recruitment firm Mercor. TeamPCP also compromised LiteLLM's own code directly, in an attack CloudSEK found had harvested secrets from more than 2,500 organisations.
The attacks even resulted in the theft of data from OpenAI, and a hack of the European Commission's cloud infrastructure.
In an audacious twist earlier this year, it was announced on Telegram that TeamPCP was running a competition offering a prize for whoever built the biggest attack with leaked Shai-Hulud code.
Supply chain attacks like Shai-Hulud exploit the fact that most developers trust open source software packages too easily, and can all too easily believe a package from a public registry is safe because thousands of others use it.
tags
Graham Cluley is an award-winning security blogger, researcher and public speaker. He has been working in the computer security industry since the early 1990s.
View all posts
Facts Only
* Two men from Western Australia were charged by the AFP, FBI, and Western Australia Police.
* The charges included data intrusion and unauthorized modification of data.
* The group is named TeamPCP.
* TeamPCP is known for a self-propagating worm called Shai-Hulud.
* Shai-Hulud spreads through open source software.
* The two charged men were principal members of the syndicate.
* Attacks resulted in compromising over 1000 global organizations.
* Over 500,000 credentials and at least 300GB of data were stolen.
* Shai-Hulud hijacks GitHub and NPM developer credentials.
* Linked hacks included compromise of Trivy, LiteLLM, Mercor, OpenAI, and the European Commission's cloud infrastructure.
Executive Summary
Two men from Western Australia were charged by the Australian Federal Police and other agencies for their alleged involvement in TeamPCP, a cybercriminal group linked to hacking software supply chains. The charges include data intrusion and unauthorized data modification. The group is known for using a self-propagating worm called Shai-Hulud to spread malicious open-source software. These attacks are estimated to have compromised over 1000 global organizations, resulting in the theft of over 500,000 credentials and at least 300GB of data.
The group's method involves poisoning popular open-source packages, allowing them to infect thousands of victims simultaneously by compromising widely-used software components. The Shai-Hulud worm targets developer credentials on platforms like GitHub and NPM, distributing compromised versions of legitimate software. This compromise has been linked to attacks against various entities, including vulnerability scanners, AI gateways, recruitment firms, and infrastructure like OpenAI and the European Commission's cloud systems. A competition was also announced on Telegram offering a prize for building the largest attack utilizing leaked Shai-Hulud code.
Full Take
The narrative focuses on the systemic vulnerability inherent in the trust placed in the open-source software supply chain. The mechanism described—poisoning widely used packages rather than direct attacks—highlights a critical failure point where collective reliance creates an exploitable asset for malicious actors. This pattern demonstrates that technical compromise, like exploiting vulnerabilities in Shai-Hulud, translates directly into massive, distributed impact across disparate systems, from individual developer credentials to major governmental and corporate infrastructure. The existence of a competition for leaked code suggests a dynamic shift from pure exploitation to the monetization and weaponization of exploit mechanisms, indicating an evolution in cybercrime strategy. The underlying implication is that security measures often focus on perimeter defense or single-point vulnerabilities, rather than addressing the trust relationships embedded within complex software ecosystems. This prompts questioning about the responsibility shared between software creators, package distributors, and end-users regarding inherited risk.
Patterns detected: ARC-0043 Motte-and-Bailey, ARC-0024 Ambiguity
Sentinel — Human
The text reads like a factual report synthesizing details from multiple sources regarding a complex cybercrime incident, exhibiting the structure of legitimate investigative journalism.
