The Australian Federal Police, Western Australia Police Force and FBI charged two Western Australian men in their early 20s over their alleged roles as principal participants in TeamPCP, a global cybercrime syndicate. Investigators allege the group injected malicious code into trusted open-source components, compromising software supply chains used by government, academic and private-sector organizations worldwide. The activity may have affected more than 1,000 organizations, exposed over 500,000 credentials and exfiltrated at least 300 GB of data, with global remediation costs estimated in the hundreds of millions of dollars.
Authorities searched properties in Cottesloe, Hamilton Hill and Mandurah and seized electronic devices; the investigation remains ongoing and further charges or arrests are possible. TeamPCP allegedly rapidly weaponized public exploits, research and malware techniques for financial, political, disruptive and attention-seeking purposes. Reporting also distinguishes the group from the original 2025 S1ngularity and Shai-Hulud incidents: TeamPCP allegedly cloned the Shai-Hulud worm, but attribution for the original attacks remains unresolved.

See the reporting duties and controls this puts on the clock.
22 events from the most recent confirmed update back to the earliest known activity.
Louis Michael Gaebler and Ruben Ian Thomson appeared in Perth Magistrates Court after the AFP charged them with a combined 14 offences over their alleged principal roles in TeamPCP.
The AFP, FBI, and Western Australia Police Force announced the arrests of two men in their early 20s alleged to have operated TeamPCP. The investigation remained ongoing, with authorities examining seized data and not ruling out further arrests or charges.
The AFP charged a 21-year-old Cottesloe man and a 23-year-old Mandurah man following warrant executions, alleging they were principal TeamPCP participants who received cryptocurrency payments. Police searched properties in Cottesloe, Hamilton Hill, and Mandurah and seized electronic devices and other items for forensic examination.
Splunk updated its "Python PTH File Creation During Package Installation" anomaly detection, motivated by TeamPCP's LiteLLM supply-chain compromise. The analytic correlates Windows Sysmon process-creation and file-creation events to identify .pth files created during package installation, which can execute code on later Python launches.
GitHub introduced a three-day cooldown for Dependabot updates, intended to provide more time to identify and remove compromised dependency releases amid widespread poisoned-package activity. Python and JavaScript package ecosystems also adopted similar cooldown-period support.
Dataminr reported that TeamPCP's May 2026 Mini Shai-Hulud campaign compromised 172 packages with 518 million cumulative downloads. The campaign reportedly targeted developer and cloud credentials and affected packages or organizations including TanStack, UiPath, Mistral AI, OpenSearch, Guardrails AI, and LiteLLM.
In May, TeamPCP claimed it had compromised at least 3,800 GitHub repositories after a GitHub developer installed an extension compromised by its malware. The group also published source code for a third Shai-Hulud iteration and reportedly offered 1,000 XMR for the largest supply-chain operation using it.
The AFP, FBI, and Western Australia Police Force began parallel investigations after the AFP and FBI received information from multiple cyber-threat assessment companies.
CISA added CVE-2026-33634, which the reporting associates with the TeamPCP supply-chain campaign, to its Known Exploited Vulnerabilities catalog.
While investigating an incident, the Aikido author encountered an attack linked to TeamPCP activity.
Investigators identified the European Commission and GitHub as downstream victims of TeamPCP's malicious Trivy release, which was distributed through automated build pipelines. They estimated the campaign exposed more than 500,000 credentials, exfiltrated at least 300 GB of data, and caused remediation costs in the hundreds of millions of dollars.
Flare reported that TeamPCP exploited a misconfigured GitHub Actions workflow in Aqua Security's Trivy project and published a malicious Trivy release that deployed credential-stealing code in CI/CD pipelines. It said LiteLLM subsequently ran the poisoned software, allowing TeamPCP to steal its PyPI token and publish two backdoored LiteLLM releases on March 24.
TeamPCP's alleged March compromise of LiteLLM packages on PyPI reportedly affected more than 2,500 organizations. Automated build systems reportedly downloaded and used the compromised packages tens of thousands of times.
Cybersecurity journalist Brian Krebs reported that arrested suspect Ruben Thomson was allegedly known online as “Ellis.” Ellis reportedly said he led TeamPCP until March 2026.
TeamPCP allegedly targeted Next.js applications in a React2Shell campaign and claimed to have compromised more than 59,000 servers in under 48 hours.
TeamPCP was first observed conducting attacks against software developers using the Shai-Hulud worm, which infects code repositories on platforms including GitHub.
Reporting linked TeamPCP's Trivy and LiteLLM supply-chain activity to a compromise of AI recruitment firm Mercor and to theft of data from OpenAI. The reference described these as additional impacts of the group's open-source package poisoning campaign.
The FBI identified the GitHub repository names "tpcp-docs" and "docs-tpcp" as TeamPCP data-exfiltration indicators, advising that their presence in an organization may indicate the worm created them using stolen credentials. The reporting also named KICS and the Telnyx Python SDK among modified tools and described the CanisterWorm, SANDCLOCK, Mini Shai-Hulud, and Miasma malware used in the campaign.
Police said they had extracted 100 terabytes of data from devices seized at one searched address and expected to extract substantially more as the TeamPCP investigation continued.
Ruben Thomson, the alleged TeamPCP leader charged alongside Michael Gaebler, was denied bail following the Western Australia cybercrime charges.
A reported Shai-Hulud wave on August 4 affected more than 400 npm packages, representing a new propagation event after the May Mini Shai-Hulud campaign.
Authorities allege that TeamPCP inserted malicious code into open-source repository software that developers unknowingly incorporated into downstream systems. The campaign potentially compromised more than 1,000 organizations, exposed more than 500,000 credentials, and exfiltrated at least 300 GB of data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
33 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcezdnet.fr
Open sourcecyberveille.ch
Open sourcereversinglabs.com
Open sourceabc.net.au
Open sourcecyberveille.ch
Open sourceresearch.splunk.com
Open sourcedataminr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.