Ethical Hacking News
The TeamPCP group has been linked to several major supply chain attacks in recent months, including a recent attack that affected over 1,000 organizations globally. The group has been charged with 14 offenses in connection with the attack, and their alleged role in the TeamPCP group has shed light on the growing threat of supply chain attacks. This article provides a detailed look at the TeamPCP group's activities and the measures that organizations can take to protect themselves against these types of attacks.
Two individuals, Louis Michael Gaebler and Ruben Ian Thomson, were arrested in Western Australia for their alleged role in TeamPCP, a cybercrime group responsible for high-profile supply chain attacks. The TeamPCP group has been linked to several major supply chain attacks, using stolen publishing credentials to compromise other organizations. The group's methods are described as "poisoned" as they introduce malicious code into compromised project's own release channels, allowing access to sensitive information. The most recent attack, attributed to TeamPCP, affected over 1,000 organizations globally, stealing over 500,000 credentials and exfiltrating at least 300 gigabytes of data. The FBI warns that organizations should treat exfiltrated data and credentials as a persistent risk, and advises rotating CI/CD secrets and publishing tokens. The TeamPCP group's activities have been tracked back to 2020, and their use of open-source platforms to launch attacks has been notable. The group's latest attack used a poisoned npm release, affecting over 300 organizations and stealing over 100,000 credentials.
The recent arrest of two individuals in Western Australia, Louis Michael Gaebler and Ruben Ian Thomson, has shed light on the growing threat of TeamPCP, a cybercrime group that has been responsible for several high-profile supply chain attacks. The case highlights the increasingly sophisticated methods used by these groups to compromise organizations and steal sensitive information.
The Australian Federal Police (AFP) has charged the two men with a combined total of 14 offenses, including possessing data with intent to commit a computer offense, unauthorized modification of data, and supplying data with intent to commit a computer offense. The charges are a result of their alleged role in the TeamPCP group, which has been linked to several major supply chain attacks in recent months.
The TeamPCP group has been particularly known for its use of stolen publishing credentials from trusted open-source projects to compromise other organizations. The group's methods are often described as "poisoned" because they introduce malicious code into the compromised project's own release channels. This allows the group to access sensitive information and steal credentials, which can then be used to launch further attacks.
The most recent attack, which was attributed to TeamPCP, affected over 1,000 organizations globally, with the group allegedly stealing over 500,000 credentials and exfiltrating at least 300 gigabytes of data. The attack was particularly notable because it used a poisoned LiteLLM release, which routes requests across large language model providers and consolidates an organization's provider keys.
The FBI has warned that organizations impacted by this campaign should treat exfiltrated data and credentials as a persistent risk, as affiliated threat actors are likely to weaponize them long after the initial compromise. The FBI has also advised organizations to rotate all continuous integration and continuous delivery (CI/CD) secrets, publish tokens, and make cloud credentials accessible during the exposure windows.
The TeamPCP group's activities have been tracked back to 2020, when they were linked to activity previously tracked as TA-NATALSTATUS and IronErn through overlapping domains, malware deployment paths, and staging techniques. The group's use of open-source platforms to launch its attacks has also been notable, with TeamPCP open-sourcing the worm framework used in the Mini Shai-Hulud campaign on GitHub in May 2026.
The group's latest attack was particularly notable because it used a poisoned npm release, which affected over 300 organizations and stole over 100,000 credentials. The attack was also notable because it was launched using the same toolkit as the group's previous attacks, which were linked to a fresh npm wave using the same toolkit on August 4, 2026.
The recent arrest of Louis Michael Gaebler and Ruben Ian Thomson has brought the TeamPCP group to the forefront of attention, highlighting the growing threat of supply chain attacks and the increasingly sophisticated methods used by cybercrime groups to compromise organizations. As the threat landscape continues to evolve, it is essential for organizations to take proactive measures to protect themselves against these types of attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/TeamPCP-The-Pivotal-Role-of-Supply-Chain-Attacks-in-the-Evolution-of-Cybercrime-ehn.shtml
https://thehackernews.com/2026/08/alleged-teampcp-hackers-charged-in.html
Published: Sat Aug 29 20:44:11 2026 by llama3.2 3B Q4_K_M