VMTech
Discuss a project

Australian police charge two over alleged TeamPCP supply-chain attacks

Australian police charge two over alleged TeamPCP supply-chain attacks

Australian Federal Police have arrested two men in Perth over alleged involvement in TeamPCP, a cybercrime group linked to supply-chain attacks against open-source software projects. The men face more than a dozen allegations spanning hacking, money laundering and other cybercrime offences, and were due to appear in court on Thursday.

Authorities allege that the operation compromised and tampered with widely used open-source projects in order to infect large numbers of computers. The alleged aim was to collect credentials and data, then extort affected victims for payment.

Alleged campaign reached more than 1,000 organizations

FBI Cyber Division chief Brett Leatherman said the two alleged TeamPCP members are accused of hacking more than 1,000 organizations. Australian officials said the group stole more than 500,000 credentials, which could then be used to expand attacks into other companies and services.

The investigation began in April 2026 after the Australian Federal Police received information from multiple cybersecurity companies. During a Wednesday press conference, officials said they seized devices, other electronics and a large quantity of allegedly stolen data. They also said they intended to notify victims.

Open-source tooling became the access route

TeamPCP is alleged to have targeted the software supply chain by altering popular open-source tools used across potentially thousands of organisations. When a modified tool was installed on a developer or company system, the malicious code could steal private keys and other credentials used to reach cloud storage and, in many cases, customer data.

One alleged operation involved Trivy, a vulnerability scanner. The incident affected organisations relying on the tool, including LiteLLM and AI recruitment startup Mercor. Investigators also suspect the group of breaching European Commission cloud infrastructure and targeting other open-source projects and developer applications that offered access to services at GitHub and OpenAI.

Credential exposure is the central operational risk

The allegations underline how a trusted developer dependency can become a route to far broader compromise when it can access secrets, build environments or cloud resources. The issue is particularly relevant where services hold reusable tokens, as exposed credentials used in an attack on Hugging Face illustrates the risk of exposed credentials being used in an attack on Hugging Face.

For businesses, the practical implication is to treat package updates and developer tools as security-critical suppliers: limit the credentials available to them, monitor for unexpected changes, and ensure that keys can be revoked quickly if a dependency is suspected of compromise.

#cybersecurity#supplychain#opensource#credentialsecurity
Open analytics
On the site 0 views
min read 3 27.08.2026
Instagram

Australian police charge two over alleged TeamPCP supply-chain attacks

Open the post on Instagram ↗