Australian Police Arrest Alleged TeamPCP Hackers Behind Shai-Hulud Worm

The Australian Federal Police have arrested two men accused of participating in TeamPCP, the hacking group tied to a supply-chain campaign that compromised more than 1,000 organizations with the self-propagating Shai-Hulud malware.

Australian Police Arrest Alleged TeamPCP Hackers Behind Shai-Hulud Worm

The Australian Federal Police have arrested two men accused of participating in TeamPCP, the hacking group tied to a sprawling software supply-chain campaign that compromised more than 1,000 organizations worldwide. The AFP said the suspects face 14 charges.

Self-Propagating Shai-Hulud Malware At The Center

TeamPCP became notorious for attacks involving Shai-Hulud, a self-propagating malware that contaminated open-source software packages and then spread through developer pipelines as companies unwittingly downloaded and incorporated compromised components. The campaign reportedly touched widely used tools including the Trivy vulnerability scanner, with infections cascading into downstream software packages.

Dependency Chains Are The New Attack Surface

The arrests underline how modern software builds — often assembled from thousands of third-party packages, libraries, scanners and CI plug-ins — can turn a single stolen maintainer credential into a global breach. Researchers have also warned that large language models are lowering the expertise barrier for sophisticated attackers by helping them research, automate and troubleshoot campaigns faster. Recent incidents such as the actively exploited Citrix NetScaler flaw and the GitLab GraphQL zero-day show how quickly opportunistic operators can weaponize public disclosures.

Cybersecurity investigators tracing supply-chain attack

Prosecution Test For Cross-Border Cybercrime

The prosecutions will be an important test of how national law enforcement handles distributed supply-chain crews whose payloads reach thousands of victims across jurisdictions. Companies are increasingly expected to inventory their dependencies, sign artifacts and treat build systems as production infrastructure, and industry-wide efforts — including the coalition described in this week's 100-firm AI cyber defense open letter — are pushing for coordinated defense.

Reporting based on coverage from Ars Technica and the Australian Federal Police.

Category: Cyber Security

Tags: Cybersecurity supply chain security open source security malware

Related Articles