The Australian Federal Police, Western Australia Police and the FBI announced the arrests on August 26.
Officers arrested two men, aged 21 and 23, in Cottesloe and Mandurah in Western Australia. During the operation, investigators seized electronic devices and other evidence for forensic analysis.
The men face a combined 14 charges. These include allegations of possessing and supplying data for computer offences. They also face allegations of modifying data to facilitate serious crimes.
One suspect also faces allegations relating to criminal proceeds and a failure to comply with an order to provide electronic data access.
Malicious packages targeted developers
TeamPCP hackers allegedly compromised trusted open-source packages and developer platforms. They then inserted malicious code into software that developers could unknowingly add to their own applications.
As a result, one compromised package can affect many downstream organisations. The impact can spread across government, academic and private-sector environments.
The group has been linked to incidents involving Trivy, LiteLLM, Telnyx, SAP and TanStack packages. It has also claimed breaches affecting several prominent organisations.
Authorities report worldwide damage
According to the AFP, malicious code connected to the alleged operation may have compromised more than 1,000 organisations worldwide.
Authorities said the activity may have enabled the theft of around 500,000 credentials. It may also have led to the exfiltration of at least 300GB of data.
In addition, the AFP estimated that global remediation costs could reach hundreds of millions of dollars. The investigation began in April 2026 after cybersecurity firms shared information with law enforcement.
Investigation could lead to more arrests
Police allege that the two men received cryptocurrency payments for their involvement in TeamPCP operations.
Authorities have not ruled out further arrests or charges. Investigators will now examine the devices and evidence collected during the operation.
The case shows why software supply-chain security remains essential. TeamPCP hackers allegedly exploited trusted components to reach a far wider group of victims.


0 responses to “Australia Arrests Alleged TeamPCP Hackers Linked to Supply-Chain Attacks”