Ethical Hacking News
The Australian Federal Police have arrested two alleged members of the notorious cybercrime group TeamPCP, highlighting the ongoing threat of sophisticated cyberattacks. The group, which rose to prominence in 2025, was known for its use of malicious open-source software to rob thousands of global businesses. The arrest of TeamPCP's alleged leaders marks a significant blow to the group, but underscores the ongoing need for vigilance in the software development community.
Two alleged members of TeamPCP, a prolific cybercrime group, were arrested in Australia. The group allegedly created malicious open-source software to rob thousands of global businesses. TeamPCP embedded malicious code in hundreds of open-source software tools, compromising corporate cloud environments. The group's tactics involved cyclical exploitation of software developers and peer community recruitment. The arrest highlights the ongoing threat of sophisticated cyberattacks and the need for increased vigilance in the software development community.
Two alleged members of the prolific cybercrime group TeamPCP were arrested in Australia in a crackdown that highlights the ongoing threat of sophisticated cyberattacks. The Australian Federal Police (AFP) arrested two men from Western Australia, aged 21 and 23, in connection with a "sophisticated cybercrime syndicate" that allegedly created malicious open-source software to rob thousands of global businesses.
TeamPCP, a group of cybercriminals from Western Australia, rose to prominence in late 2025 by embedding malicious code in hundreds of open-source software tools. The group's tactics involved compromising corporate cloud environments using a self-propagating worm dubbed Shai-Hulud, which added malicious code to open-source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen.
The group's core tactic was a kind of cyclical exploitation of software developers, where hackers gain access to a network where an open-source tool commonly used by coders is being developed, and then plant malware in the tool that ends up on other software developers' machines, allowing the hackers to steal credentials that let them publish malicious versions of those software development tools, too.
TeamPCP also practiced something akin to cyclical recruitment, launching a contest offering $1,000 in virtual currency to participants who could conduct the largest supply chain operation using the worm's code. The contest rules scored participants based on the number of weekly and monthly downloads of packages they compromised, directly incentivizing them to target the most popular code libraries.
The group's operations were facilitated by a peer community of individually skilled actors, with one clear center of gravity in George Prepakis, a self-described exploit developer who operated the Twitter/X profile @kernelstub. The group's leader, George Prepakis, or Ellis as he is also known, was interviewed by KrebsOnSecurity in early July 2026. In the interview, Ellis claimed that he stopped doing cybercrime for TeamPCP in March 2026, just before the attacks that compromised LiteLLM, and that another individual has taken over the group's leadership since then.
Ellis's struggles with sobriety were also apparent during the interview, as he discussed his addiction to methamphetamine and DMT, a powerful psychedelic compound. He expressed no remorse for his cybercrime activities and seemed resigned to his fate, saying that he would accept the consequences if he were ever arrested.
The arrest of TeamPCP's alleged leaders highlights the ongoing threat of sophisticated cyberattacks and the need for increased vigilance in the software development community. Charlie Eriksen, a security researcher at Aikido Security, noted that TeamPCP's legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years.
Related Information:
https://www.ethicalhackingnews.com/articles/Unmasking-TeamPCP-The-Rise-and-Fall-of-a-Notorious-Cybercrime-Syndicate-ehn.shtml
https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/
Published: Sat Aug 29 07:36:42 2026 by llama3.2 3B Q4_K_M