Two Members of TeamPCP, a Cybercriminal Group Specializing in Software Supply Chain Attacks, Arrested in Australia

Australian authorities have arrested two men believed to be members of TeamPCP, a cybercriminal group known for carrying out the longest series of software supply chain attacks ever recorded. In a statement released today, the Australian Federal Police (AFP) said the two men, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that would have created malicious open-source software to rob thousands of global businesses."

TeamPCP's Tactics

TeamPCP emerged on the cybercrime scene at the end of 2025, incorporating malicious code into hundreds of open-source software tools and extorting victims for profit. The group gained notoriety by compromising corporate cloud environments using a self-propagating worm called Shai-Hulud, which added malicious code to open-source programs maintained by developers whose credentials on public code repositories like GitHub or NPM had been phished or stolen.

Writing for Wired, journalist Andy Greenberg described TeamPCP's main tactic as a sort of cyclic exploitation of software developers. "The hackers gain access to a network where a commonly used open-source tool by developers is being developed. The hackers plant malware in the tool that ends up on the machines of other software developers, including some who are writing other tools intended for use by developers. The malware allows TeamPCP hackers to steal the credentials that allow them to publish malicious versions of those software development tools. The cycle repeats and the collection of networks violated by TeamPCP grows."

The Cyclic Recruitment

TeamPCP also practiced a sort of cyclic recruitment. In May, the source code of the third iteration of Shai-Hulud was published online and TeamPCP then launched a contest offering 1,000 units of virtual currency to anyone who could carry out the largest supply chain operation using the worm's code. According to the contest rules, participants were evaluated based on the number of weekly and monthly downloads of the packages they had compromised, directly incentivizing them to target the most popular code libraries.

Recent Attacks

In March 2026, TeamPCP carried out a supply chain attack targeting AI infrastructure, compromising the code of LiteLLM, an open-source AI gateway that connects users to more than 100 different large language models. A recent analysis by security firm CloudSEK revealed that TeamPCP's attack on LiteLLM collected cloud service keys and other secrets from more than 2,500 organizations, including many of the world's leading tech companies.

In May, TeamPCP claimed responsibility for the compromise of at least 3,800 code repositories on GitHub, owned by Microsoft, after a GitHub developer installed a code extension compromised by TeamPCP's malware.

The Cybercats

Security experts say TeamPCP is less a hacker group than an amalgam of threat actors from multiple cybercriminal gangs who sometimes work together to achieve similar goals. "It's not a structured criminal crew with a single operator. It's a peer community with individually capable actors, with a clear center of gravity," said Austin Larsen, principal threat analyst at the Google Threat Intelligence Group.

That center of gravity is George Prepakis, a self-proclaimed expert security researcher and exploit developer who manages the Twitter/X profile [@kernelstub](https://x.com/kernelstub). Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and named "Cybercats," and TeamPCP and several other cybercriminal entities have used this server to communicate daily for the past few months.

Kernelstub, like other administrators in the Cybercats chat, used his Twitter/X profile name as a handle in these Matrix communications, frequently tweeting references to other members and ongoing conversations in the Cybercats chat. In several cases, the corresponding X accounts for Cybercats chat members publicly mocked cybercrime victims before the incidents were reported in the media.

Who is the Leader of TeamPCP?

TeamPCP is not a traditional hierarchical organization, but rather a community of threat actors who collaborate occasionally. This decentralized structure allows the group to operate flexibly and adaptably, with various members contributing their specific skills.

A key element of this community is the Matrix chat server called "Cybercats," created and managed by George Prepakis, also known as @kernelstub on Twitter/X. This communication space has facilitated collaboration between TeamPCP and other cybercriminal entities, allowing the sharing of information and strategies. The server administrators, including Kernelstub and Boxturtle, used their Twitter/X profiles as handles in communications, creating a link between online and offline activities.

Challenges for Law Enforcement

The decentralized nature of TeamPCP and its ability to exploit a network of independent actors make it difficult for law enforcement to track and arrest key members. However, the recent arrests in Australia demonstrate that authorities are making progress in understanding the group's structure and strategies to counter it.

The use of platforms like Twitter/X and Matrix for public communication has left digital traces that could be used to identify and prosecute TeamPCP members. Additionally, international collaboration between agencies such as the AFP, FBI, and Western Australia Police Force is essential to address a threat that operates on a global scale.

Implications for Cybersecurity

TeamPCP's attacks underscore the importance of adopting robust security measures to protect software supply chains. Companies must implement strict controls to verify the integrity of open-source code and closely monitor suspicious activities within their networks.

Furthermore, the cybersecurity community must remain vigilant and collaborate to share information about new threats and tactics used by cybercriminals. The creation of alliances between companies, security researchers, and law enforcement is fundamental to effectively counter groups like TeamPCP and prevent future attacks.

Conclusions

TeamPCP represents one of the most significant threats in the cybercrime landscape, thanks to its ability to exploit software supply chain vulnerabilities and recruit a network of talented hackers. The recent arrests in Australia are an important step, but the fight against this group requires ongoing commitment and international collaboration.

For companies and individuals, the lesson is clear: cybersecurity is not an option, but an absolute necessity in an increasingly connected and vulnerable world to cyber attacks.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.

📰 Source: krebsonsecurity.com ↗
✍️ Elaboration: Sebastiano · GoYou.it