Australian Police Detain Two Suspects Tied to TeamPCP Supply-Chain Attacks

Two men aged 21 and 23 from Western Australia were arrested on suspicion of membership in the TeamPCP group, which authorities link to the longest-running campaign of malicious open-source software attacks on record.

The Arrests

The Australian Federal Police announced the arrests of two unnamed suspects from Western Australia. The men, aged 21 and 23, face charges connected to a cybercrime syndicate accused of creating malicious open-source software that targeted thousands of global businesses. The AFP described the operation as the work of a sophisticated group responsible for an extended series of software supply-chain attacks.

The statement from the AFP tied the suspects directly to the creation and distribution of tainted open-source tools used for data extortion. No further identifying information or court documents have been released at this stage. The agency characterized the group as one that allegedly created malicious open-source software to rob thousands of global businesses.

Background on TeamPCP Activity

TeamPCP had previously operated without public arrests despite ongoing activity. The group gained attention for embedding malicious code in open-source packages that developers and companies downloaded and deployed. Prior to these arrests, the only public details came from security researchers tracking the campaign and from KrebsOnSecurity, which identified the 21-year-old suspect in June and maintained contact with him afterward.

The AFP statement positioned the arrests as a response to a long-running pattern of supply-chain compromises. The group’s method centered on inserting harmful code into packages hosted in public repositories, allowing the tainted software to spread through normal developer workflows. This approach avoided direct targeting of individual companies and instead relied on the trust placed in widely used open-source components.

Reporting Details from KrebsOnSecurity

KrebsOnSecurity reporting notes that the 21-year-old suspect had spoken with the outlet over several months. The same coverage includes interviews with a self-described TeamPCP spokesperson and analysis of technical clues left in the group’s infrastructure. The publication learned the 21-year-old suspect’s real identity in June and continued communicating with him in the period leading up to the arrests.

The article examined infrastructure details and statements from the group’s self-described spokesperson. These elements provided additional context on how the operation was structured and maintained over time. The AFP did not confirm or deny any connection to the specific individual previously identified in the reporting.

Why it matters

Open-source supply chains remain a high-value target because a single compromised package can reach thousands of downstream users without additional effort from the attacker. The arrests show that even small teams can sustain long campaigns when they focus on trusted distribution points rather than individual breaches. For developers and companies that rely on public repositories, the case underscores the need for stronger verification steps before pulling dependencies into production systems.

Routine code review and reproducible builds offer more practical protection than waiting for law-enforcement action against the next group to adopt the same tactic. When malicious code travels through legitimate update channels, traditional perimeter defenses provide limited value. Organizations that treat every dependency update as an untrusted input reduce the blast radius of any future compromise.

The arrests also highlight the limits of relying solely on law enforcement to address persistent supply-chain threats. While these actions remove specific actors from circulation, the underlying attack surface stays intact. Teams that implement signed commits, pinned versions, and automated scanning for known malicious patterns gain an operational edge that does not depend on the timing of future police operations.

The TeamPCP case demonstrates how modest technical skills applied consistently over months or years can produce widespread impact. Defenders who focus on the mechanics of package publication and consumption gain visibility into changes that would otherwise pass unnoticed. That visibility, rather than any single arrest, determines whether similar campaigns succeed or fail in the future.

---

Sources:

{"word_count": 612, "sources_used": ["https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/"]}

No comments yet