Australia Arrests Two Alleged TeamPCP Hackers Behind Record

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Australian Federal Police arrested two Western Australian men (ages 21 and 23) tied to TeamPCP, a group the AFP says ran the "longest running spree of software supply chain attacks ever" by embedding malicious code in open-source tools and extorting victims
- TeamPCP's Shai-Hulud worm self-propagates by stealing developer credentials from GitHub and NPM, then poisoning the open-source packages those developers maintain — a cycle journalist Andy Greenberg (Wired) described as cyclical exploitation of software supply chains
- TeamPCP ran a $1,000 Monero contest scored by weekly and monthly downloads of compromised packages; security firm Dataminr says the contest was 'a recruitment floor' and TeamPCP's true intent was 'talent identification and malicious access acquisition at scale'
- TeamPCP's March attack on LiteLLM — an open-source AI gateway connecting users to 100+ large language models — harvested cloud service keys from more than 2,500 organizations, including many of the world's top technology companies, per CloudSEK
- TeamPCP claimed in May it compromised at least 3,800 code repositories at Microsoft-owned GitHub after a developer installed a compromised code extension
- Google Threat Intelligence Group principal analyst Austin Larsen told KrebsOnSecurity that TeamPCP is 'not a structured criminal crew with a single operator' but 'a peer community of individually-skilled actors, with one clear center of gravity' — security researcher George Prepakis (@kernelstub), who runs the Cybercats Matrix chat server
- @pcpcasper, one of the two arrested, has an extensive Telegram message history showing him as an active member of Australia's National Socialist Network, a neo-Nazi political organization; cat videos he shared placed him in Western Australia
- TeamPCP's leader (@pcpcats, aliases EllisD25/LSD, BulkDMT, Express) registered on Breachforums with shitstickpp@gmail.com, used South African IP addresses in 2025, complained 'my whole country is racist and they want people like me dead,' and posted about recovering from methamphetamine addiction
Why it matters: The arrests hit a loose network — not a structured crew — whose Shai-Hulud worm turned poisoned npm and GitHub packages into a self-replicating credential harvester, with one March LiteLLM compromise alone pulling cloud keys from 2,500+ organizations including top tech firms. Google Threat Intelligence's framing matters for defenders: if TeamPCP is a peer community centered on a single researcher, taking out nodes doesn't necessarily stop the worm's code from circulating on cybercrime forums.
Ask SkimNews



