Australian Police Arrest Two Alleged Members of Supply-Chain Extortion Crew TeamPCP
The Western Australia arrests target a group blamed for a year-long run of open-source software attacks, including the Shai-Hulud worm that hit thousands of companies.

Key points
- The Australian Federal Police arrested two men, aged 21 and 23, in Western Australia over their alleged roles in the cybercrime group TeamPCP.
- TeamPCP is blamed for the longest-running spree of software supply-chain attacks on record, poisoning hundreds of open-source coding tools since late 2024.
- The group's Shai-Hulud worm stole cloud keys from more than 2,500 organisations through a single attack on the AI tool LiteLLM, according to security firm CloudSEK.
- TeamPCP claimed credit for tampering with at least 3,800 code projects on GitHub after a developer installed a booby-trapped extension.
- The group ran a $1,000 Monero contest in May to recruit hackers who could poison the most popular software packages.
Australian Federal Police have arrested two men in Western Australia over their alleged roles in TeamPCP, a cybercrime crew blamed for the longest-running spree of software supply-chain attacks ever documented.
Police named neither suspect. They are 21 and 23. In a statement, the AFP described the pair as part of a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses."
TeamPCP is not a normal gang. Security researchers describe it as a loose peer group of skilled hackers who drift between crews and share a Matrix chat server called Cybercats. The reporting on the group's inner workings, and on the identity of the 21-year-old suspect, was first published by KrebsOnSecurity.
Who is TeamPCP?
A loose crew of hackers who poison open-source software, the free code that almost every app and website is built on top of. They sneak malicious code into popular developer tools, then use those tools to steal from the companies that install them.
The group surfaced in late 2024 and quickly made a name for itself with a self-spreading program called Shai-Hulud. The worm, which is a piece of malware that copies itself from one victim to the next automatically, hunts for developer passwords stored on infected machines. When it finds them, it uses those passwords to publish tainted updates of other coding tools, and the cycle repeats.
Andy Greenberg at Wired described the tactic as "cyclical exploitation of software developers." Each new victim becomes the launch pad for the next attack.
How big was the damage?
Larger than most supply-chain incidents on record. Two attacks alone reached thousands of companies through a single poisoned tool.
In March, TeamPCP tampered with LiteLLM, a free tool that connects apps to more than 100 AI models. Security firm CloudSEK found the attack harvested cloud service keys and other secrets from more than 2,500 organisations, including several of the world's largest technology firms.
Two months later, the group claimed credit for compromising at least 3,800 code projects hosted on GitHub, the Microsoft-owned site where most of the world's software is stored. The entry point was a single developer installing a booby-trapped code extension.
| Incident | Date | Scale |
|---|---|---|
| LiteLLM AI gateway attack | March 2025 | Secrets stolen from 2,500+ organisations |
| GitHub extension attack | May 2025 | 3,800+ code projects compromised |
| Shai-Hulud recruitment contest | May 2025 | $1,000 Monero prize per winner |
| AFP arrests, Western Australia | This week | 2 suspects, aged 21 and 23 |
How did investigators find them?
Through their own online chatter. Members of the Cybercats Matrix chat used the same handles on Twitter/X, where they taunted victims and boasted about breaches before the news broke.
One administrator, posting as @pcpcasper, shared videos of a pet cat that placed him in Western Australia. He was also an active member of an Australian neo-Nazi group on Telegram. A second administrator, using the handle T, ran the now-banned account @pcpcats and served as the group's self-described spokesperson. Sources told KrebsOnSecurity that both handles map to the two men arrested this week.
Should ordinary businesses worry?
Yes, indirectly. Most companies do not write software, but they run it. If a supplier's coding tools were poisoned by TeamPCP, credentials and cloud keys inside that supplier may have been stolen and resold.
Data allegedly tied to the wider Cybercats circle has been offered for sale on criminal forums, including records from BMW, Audi, Honda, Mercedes-Benz, Volvo, Toyota, Snapchat and SportRadar. Customers of those firms should watch for unusual account activity and phishing emails referencing recent purchases or service records.



