ELSEIF
Your brief EB
442 stories from 137 feeds 658 clusters Refreshed 1 minute ago next pull 13:39

SECURITY Signal 518

Australian police arrest two alleged TeamPCP hackers tied to massive open-source supply chain attacks

Illustration only Photo by Aneta Pawlik on Unsplash

Australian Federal Police arrested two men in Western Australia accused of being part of TeamPCP, a group blamed for extensive software supply chain attacks using malicious open-source tools.

WHY IT MATTERS

The arrests target a group that successfully compromised thousands of organizations by poisoning open-source development tools and AI infrastructure. For engineering teams, this highlights the persistent risk of credential theft and malicious code injection within public repositories like GitHub and NPM.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Australian police arrested two unnamed men, aged 21 and 23, allegedly belonging to the TeamPCP cybercrime group.

02

TeamPCP used a self-propagating worm named Shai-Hulud to inject malicious code into open-source tools after stealing developer credentials.

03

The group compromised an AI gateway called LiteLLM, harvesting secrets from over 2,500 organizations, and claimed credit for compromising 3,800 GitHub repositories.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Krebs on Security Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Open ↗