Two West Australian men were charged yesterday (26 August 2026) following a joint investigation by the AFP, WA Police Force, and FBI into TeamPCP, one of the most damaging open-source supply chain attack campaigns of the year. Both are due to appear in Perth Magistrates Court today.
Who TeamPCP were
TeamPCP first surfaced in late 2025, also operating under aliases including DeadCatx3, PCPcat, ShellForce, and CipherForce. Rather than phishing individuals, the group targeted misconfigured cloud services, exposed Docker APIs, Kubernetes clusters, and vulnerable web applications, using them as a platform to gain access to victims’ GitHub repositories and push malicious updates into widely-used software.
Their campaign compromised security tools including Aqua Security’s Trivy, Checkmarx KICS, LiteLLM, Telnyx, Palo Alto Networks, and more than 66 npm packages, with the malicious code reaching as far as the European Commission’s AWS environment. The group later moved from straightforward credential theft into extortion, publishing victim names on a public leak site and working with other cybercriminal groups to monetise stolen access.
The scale is what made this campaign stand out: over 1,000 SaaS environments affected, roughly 500,000 credentials stolen, and more than 300 GB of data exfiltrated, with global remediation costs now estimated in the hundreds of millions of dollars.
The arrests
Investigations began in April 2026, after the AFP and FBI received information from multiple cyber threat assessment companies about a syndicate inserting malicious code into open-source software that was then unwittingly redistributed into government, academic, and private-sector systems worldwide.
Search warrants were executed yesterday at properties in Cottesloe, Hamilton Hill, and Mandurah, with electronic devices and other items seized for forensic analysis. Police allege both men were principal participants who received cryptocurrency payments for their roles.
A 21-year-old Cottesloe man has been charged with possessing data with intent to commit a computer offence, four counts of unauthorised modification of data with intent to commit a serious offence, supplying data with intent to commit a computer offence, failing to comply with a 3LA order, and dealing with proceeds of crime worth $100,000 or more. A 23-year-old Mandurah man faces possessing data with intent to commit a computer offence, four counts of unauthorised modification of data with intent to commit a serious offence, and supplying data with intent to commit a computer offence — 14 charges between them.
FBI Cyber Division Assistant Director Brett Leatherman confirmed the men are alleged members of TeamPCP. AFP Commander Graeme Marshall noted that cybercrime syndicates are becoming increasingly organised, often operating like professional businesses. Further arrests haven’t been ruled out, and a large volume of seized data remains under forensic examination.
Why this matters for businesses
TeamPCP didn’t need to breach any single business directly. They compromised trusted, widely-used open-source tools upstream, and every organisation that pulled in a poisoned update inherited the compromise automatically. That’s the uncomfortable part of this story for any business relying on open-source software, which is to say almost every business: the attack surface isn’t just your own code and infrastructure, it’s every dependency you trust and every developer credential sitting in your GitHub org.
If you want help understanding your exposure to supply chain risk, or reviewing what access your CI/CD pipelines and repositories actually have, get in touch.
Source: Mirage News
Contact us
Let's discuss how we can help protect your business and achieve your security goals.