The Australian Federal Police, Western Australia Police Force and FBI charged two Western Australian men in their early 20s over their alleged roles as principal participants in TeamPCP, a global cybercrime syndicate. Investigators allege the group injected malicious code into trusted open-source components, compromising software supply chains used by government, academic and private-sector organizations worldwide. The activity may have affected more than 1,000 organizations, exposed over 500,000 credentials and exfiltrated at least 300 GB of data, with global remediation costs estimated in the hundreds of millions of dollars.
Authorities searched properties in Cottesloe, Hamilton Hill and Mandurah and seized electronic devices; the investigation remains ongoing and further charges or arrests are possible. TeamPCP allegedly rapidly weaponized public exploits, research and malware techniques for financial, political, disruptive and attention-seeking purposes. Reporting also distinguishes the group from the original 2025 S1ngularity and Shai-Hulud incidents: TeamPCP allegedly cloned the Shai-Hulud worm, but attribution for the original attacks remains unresolved.

Trace attribution and downstream blast radius.
13 events from the most recent confirmed update back to the earliest known activity.
Louis Michael Gaebler and Ruben Ian Thomson appeared in Perth Magistrates Court after the AFP charged them with a combined 14 offences over their alleged principal roles in TeamPCP.
The AFP, FBI, and Western Australia Police Force announced the arrests of two men in their early 20s alleged to have operated TeamPCP. The investigation remained ongoing, with authorities examining seized data and not ruling out further arrests or charges.
The AFP charged a 21-year-old Cottesloe man and a 23-year-old Mandurah man following warrant executions, alleging they were principal TeamPCP participants who received cryptocurrency payments. Police searched properties in Cottesloe, Hamilton Hill, and Mandurah and seized electronic devices and other items for forensic examination.
GitHub introduced a three-day cooldown for Dependabot updates, intended to provide more time to identify and remove compromised dependency releases amid widespread poisoned-package activity. Python and JavaScript package ecosystems also adopted similar cooldown-period support.
In May, TeamPCP claimed it had compromised at least 3,800 GitHub repositories after a GitHub developer installed an extension compromised by its malware. The group also published source code for a third Shai-Hulud iteration and reportedly offered 1,000 XMR for the largest supply-chain operation using it.
The AFP, FBI, and Western Australia Police Force began parallel investigations after the AFP and FBI received information from multiple cyber-threat assessment companies.
While investigating an incident, the Aikido author encountered an attack linked to TeamPCP activity.
Investigators identified the European Commission and GitHub as downstream victims of TeamPCP's malicious Trivy release, which was distributed through automated build pipelines. They estimated the campaign exposed more than 500,000 credentials, exfiltrated at least 300 GB of data, and caused remediation costs in the hundreds of millions of dollars.
Flare reported that TeamPCP exploited a misconfigured GitHub Actions workflow in Aqua Security's Trivy project and published a malicious Trivy release that deployed credential-stealing code in CI/CD pipelines. It said LiteLLM subsequently ran the poisoned software, allowing TeamPCP to steal its PyPI token and publish two backdoored LiteLLM releases on March 24.
Cybersecurity journalist Brian Krebs reported that arrested suspect Ruben Thomson was allegedly known online as “Ellis.” Ellis reportedly said he led TeamPCP until March 2026.
The FBI identified the GitHub repository names "tpcp-docs" and "docs-tpcp" as TeamPCP data-exfiltration indicators, advising that their presence in an organization may indicate the worm created them using stolen credentials. The reporting also named KICS and the Telnyx Python SDK among modified tools and described the CanisterWorm, SANDCLOCK, Mini Shai-Hulud, and Miasma malware used in the campaign.
Ruben Thomson, the alleged TeamPCP leader charged alongside Michael Gaebler, was denied bail following the Western Australia cybercrime charges.
Authorities allege that TeamPCP inserted malicious code into open-source repository software that developers unknowingly incorporated into downstream systems. The campaign potentially compromised more than 1,000 organizations, exposed more than 500,000 credentials, and exfiltrated at least 300 GB of data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
16 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourcetechcrunch.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcemalware.news
Open sourcekrebsonsecurity.com
Open sourceafp.gov.au
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.