Australian police arrest two alleged members of TeamPCP supply-chain crew

The pair, from Western Australia, are linked to a hacking collective that poisoned open-source software used by thousands of companies, and to the extortion crew Fulcrumsec.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Photoreal news-editorial overhead shot of a developer's dark wooden desk, glowing laptop screen showing an abstract green-on-black code repository interface wit
Share

Key points

  • Australian Federal Police arrested two men, aged 21 and 23, from Western Australia over their alleged roles in TeamPCP, a hacking group that hid malicious code inside widely used open-source software.
  • One arrested man is linked in reporting to the online handle @pcpcasper, an active member of an Australian neo-Nazi group; the other used the alias @pcpcats and described himself as the group's spokesperson.
  • TeamPCP is tied through a private Matrix chat server called Cybercats to Fulcrumsec, a separate extortion crew that has claimed attacks on Novo Nordisk, LexisNexis, Avnet and others.
  • Threat Vectr's own leak-site tracking has logged 27 victims claimed by Fulcrumsec since May 2026, with 2 added in the past 30 days, most of them technology firms.
  • A March supply-chain attack on the open-source AI tool LiteLLM harvested cloud keys and secrets from more than 2,500 organisations, according to security firm CloudSEK.

Australian Federal Police have arrested two men in Western Australia over their alleged part in TeamPCP, a hacking collective that spent the past year hiding malicious code inside popular open-source software, the free programming building blocks that most modern apps are made from.

Police didn't name the suspects. KrebsOnSecurity, which identified the younger man in June, reports he used the handle @pcpcasper and belongs to the National Socialist Network, an Australian neo-Nazi organisation. The second man went by @pcpcats and described himself publicly as TeamPCP's spokesperson.

What did TeamPCP actually do?

They poisoned the software supply chain. They sneaked booby-trapped code into free programming tools that developers download and build into their own products, so one break-in quietly spread to thousands more.

The crew's signature tool was a self-spreading program called Shai-Hulud. Once it landed on a developer's machine, it stole the login credentials that person used to publish code on public repositories like GitHub and NPM, then used those credentials to publish tainted versions of yet more tools. Each new victim became a launchpad for the next round. We first reported on Shai-Hulud on 2 June 2026, and have since tracked it across seven stories.

In March, TeamPCP tampered with LiteLLM, an open-source gateway connecting apps to more than 100 different AI models. CloudSEK found the attack scooped up cloud service keys and other secrets from more than 2,500 organisations, including several of the world's largest technology companies. Worth noting: our 14 August report found that almost all that damage traced to a Trivy scanner compromise, not the LiteLLM package itself, and stolen credentials were already on sale by then. In May, the group claimed to have tampered with at least 3,800 code projects on GitHub after a single developer installed a poisoned browser extension.

Who are the Cybercats?

They're a loose network of hackers, not a single gang. Investigators say TeamPCP shares a private Matrix chat server called Cybercats with several other crews who occasionally work together.

Google's Threat Intelligence Group describes the setup as "a peer community of individually-skilled actors, with one clear center of gravity." One administrator on that server, using the handle SeesawSec, runs Fulcrumsec, which has publicly claimed data theft attacks on Novo Nordisk, LexisNexis and Avnet. Threat Vectr's own tracking of criminal leak sites has recorded 27 Fulcrumsec victims since May 2026, across nine sectors, with two more listings in the last 30 days. These are unverified claims the criminals published themselves, not confirmed breaches.

Should ordinary people worry?

Probably not directly, but the effects ripple outward. If you use banking apps or corporate services, some of your data may have flowed through systems that depended on the poisoned tools. Turn on multi-factor authentication, the second verification step sent to your phone, wherever it's offered. That single step would've blunted several of TeamPCP's account takeovers, because stolen developer passwords alone wouldn't have been enough.

Arresting two people won't end this. Cybercats has other administrators, and the Shai-Hulud source code has been public since May, when TeamPCP ran a contest paying $1,000 in Monero cryptocurrency to whoever poisoned the most-downloaded packages. That code is still out there, and so is the recipe.

Detail What we know
Arrests 2 men, aged 21 and 23, Western Australia
Group TeamPCP, active since late 2025
LiteLLM victims 2,500+ organisations (CloudSEK)
GitHub repos hit 3,800+ claimed, May 2026
Fulcrumsec listings 27 since May 2026 (Threat Vectr tracking)
© 2026 Threat Vectr