Breaking
Cyber CrimeDeveloping Story

TeamPCP arrests expose supply chain risk

Alleged masterminds of TeamPCP, tied to Shai-Hulud worm, arrested in Perth with FBI help.

··2 hours ago·4 min read
red padlock on black computer keyboard
Photo by FlyD on Unsplash

In a quiet suburb of Perth, one of the world's most isolated cities, Australian Federal Police officers moved in on two men they say ran a cybercrime syndicate that spread malicious code through software trusted by thousands of developers. The pair, aged 21 and 23, were arrested on Wednesday in connection with TeamPCP, a crew allegedly behind a series of supply chain attacks that compromised organizations globally. The FBI assisted in the investigation, underscoring the reach of international law enforcement even to a city thousands of miles from major tech hubs.

Masterminds in Perth

The AFP said the two men, whose identities have been partially released, were “principal participants in the activities of the cybercrime syndicate and received payments in cryptocurrency for their roles in the illegal activity.” An FBI Facebook post named one of the arrested men as Ruben Thomson, describing him as “the alleged leader of the cybercriminal group TeamPCP.” Australian media identified the second as 23-year-old Louis Michael Gaebler.

The arrests were the culmination of an investigation that began in April 2026, after the AFP and FBI “received information from multiple cyber threat assessment companies regarding a syndicate that allegedly inserted malicious code into software available on an open-source repository, which was then unwittingly used by other developers.”

The Shai-Hulud Worm

Among TeamPCP's known tools was the Shai-Hulud worm, a piece of malware that targeted npm packages, a popular ecosystem for JavaScript developers. According to prior reporting, the worm attempted to infect packages and then searched for credentials to major public clouds and services like GitHub. If successful, it would either try to replicate itself to continue attacks or wipe the environment, a destructive payload that could cripple affected systems.

The worm's name, inspired by the sandworms of Frank Herbert's Dune, hints at the group's apparent fondness for destructive chaos. But the damage was real: the AFP estimates that TeamPCP's supply chain attacks “potentially compromised more than 1000 organisations globally, enabling the theft of more than 500,000 credentials, and the exfiltration of at least 300 gigabytes of data.”

Supply Chain Attacks Under Scrutiny

The investigation revealed that the syndicate inserted malicious code into open-source software, which was then unwittingly included in projects by developers who trusted the source. This method, known as a supply chain attack, has become a growing concern in the cybersecurity community, as it can spread rapidly through software dependencies.

Researchers had already flagged some of TeamPCP's activities before the April investigation. In March, for instance, reporters at The Register noted that researchers spotted a supply chain attack on Trivy, an open-source vulnerability scanner. That incident is now understood to be linked to the same syndicate.

The scope of the compromise is significant, but the AFP has not yet detailed which specific organizations were affected. The agency said it is continuing to examine seized data.

Arrests and Seizures

The arrests took place at two different locations in Perth's suburbs, with a third property also searched. Authorities seized electronic devices and other items from the suspects, which are now being forensically examined.

“A large volume of data seized is being forensically examined and the investigation remains ongoing,” the AFP wrote, adding “Further arrests and charges have not been ruled out.”

The AFP's announcement, headlined with a casual “We cuffed 'em!”, belied the seriousness of the operation. The investigation involved coordination with the FBI, reflecting the cross-border nature of modern cybercrime.

Financial Impact in the Hundreds of Millions

Beyond the immediate data losses, the financial toll is staggering. Australia's Federal Police estimate “the financial impact includes global remediation costs estimated to be hundreds of millions of dollars.” This figure accounts for the work needed to identify compromised systems, rotate credentials, and rebuild affected infrastructure.

While the suspects received payments in cryptocurrency, the true cost is borne by the organizations that unwittingly used the tainted software. For many, the aftermath involves weeks or months of cleanup, not to mention potential regulatory fines and reputational damage.

The case highlights a paradox: the same open-source tools that empower developers also provide an attack surface for malicious actors. A single compromised package can ripple through thousands of projects, as evidenced by the scale of this campaign.

Key Statistics at a Glance

  • More than 1,000 organizations globally potentially compromised
  • Over 500,000 credentials stolen
  • At least 300 gigabytes of data exfiltrated
  • Global remediation costs estimated in the hundreds of millions of dollars

What This Means for You

For businesses and developers, the arrests may offer some relief, but the underlying lesson remains. Supply chain attacks exploit trust, and the open-source ecosystem relies heavily on the assumption that code is safe. This incident should prompt organizations to scrutinize their dependencies, monitor for unusual activity in their software build pipelines, and ensure that compromised credentials are rotated promptly.

While law enforcement has struck a blow against TeamPCP, the broader threat of supply chain attacks is unlikely to fade. As the AFP noted, further arrests are possible, suggesting the network may have more members at large. In the meantime, the case serves as a reminder that cybercriminals are increasingly targeting the software supply chain, and that even the most isolated cities are not beyond their reach.

#teampcp#shai-hulud#supply-chain-attack#australia#fbi

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories