supply-chaintrade-pressNewsThe Broadside1 min read

Australia charges two for TeamPCP supply-chain attacks

Two arrests in Perth, but the worm code went public in May and the campaign is already spawning copycat attacks.


TL;DR

Australian Federal Police charged two Perth men Wednesday over their alleged roles in TeamPCP, the cybercrime group behind a cascading series of supply-chain attacks that compromised more than 1,000 organizations globally, exposed over 500,000 credentials, and stole at least 300 gigabytes of data. The men face a combined 14 charges and up to 82 years in prison if convicted on all counts. But the arrests don't change the calculus for the thousand-plus organizations already compromised: Unit 42 has warned that TeamPCP's open-sourced worm code was already spawning copycat attacks, and that the malware "is no longer scoped to TeamPCP."

Australian Federal Police charged two Perth men Wednesday over their alleged roles in TeamPCP, the group behind one of the most damaging supply-chain hacking campaigns in recent memory. The men (identified by ABC Australia as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23) face 14 counts between them, including unauthorized modification of data and dealing in proceeds of crime exceeding $100,000.

The campaign's arc, running from at least March, hit developer tools first and cascaded outward. TeamPCP compromised TanStack and Trivy before breaching LiteLLM, an open-source Python package with three million daily downloads used across AI environments. Downstream victims included the European Commission, where attackers exfiltrated 92 gigabytes of data from the bloc's AWS infrastructure. GitHub confirmed in June that a poisoned VS Code extension gave the group access to roughly 3,800 internal repositories. Red Hat pulled 32 tainted packages the same month after attackers used a compromised GitHub account to distribute the Mini Shai-Hulud worm variant.

For practitioners, the arrests don't change as much as the headlines suggest. Palo Alto's Unit 42 warned in June that TeamPCP's full worm source code was published online in May, spawning copycat activity. The malware, Unit 42 concluded, "is no longer scoped to TeamPCP." The AFP says the seized data is still being examined and further arrests are possible, but the code that powered the campaign is already circulating beyond any two defendants. The operational threat doesn't end with a charge sheet in Perth.


Published ·Deep Fathom

Australia charges two for TeamPCP supply-chain attacks — The Broadside