Blog

TeamPCP Takedown: Two Arrests End a Year of Developer Supply-Chain Attacks

Written by tortue974 - August 27, 2026

Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group, the collective behind a string of far-reaching supply-chain attacks that haunted developers for the past year. The men, aged 21 and 23, were arrested on August 26, 2026 in the western Australian cities of Cottesloe and Mandurah.

TeamPCP built its reputation on attacking open-source software and developer platforms to steal credentials, authentication secrets and source code. High-profile incidents attributed to the group have touched Trivy, LiteLLM, Telnyx, SAP and TanStack packages, while separate breaches were carried out against the European Commission, Mistral AI, OpenAI and GitHub.

The method was simple and cruel at the same time. The attackers injected malicious code into software hosted on open-source repositories, and developers then unknowingly incorporated that code into their own applications and systems - including systems used by government, academic and private-sector organizations. Nothing was forced; the victims installed the poison themselves, one dependency at a time.

Rather than a cohesive crew, investigators describe a loose-knit collective of threat actors who all frequented the same hacking forums, Discord servers and Telegram channels. According to the Australian Federal Police, the FBI and Western Australia Police, malicious code distributed by TeamPCP has potentially compromised over a thousand organizations worldwide, enabling the theft of half a million credentials and the exfiltration of at least 300GB of data.

The alleged compromise of a small number of trusted software components had a significant global impact, the AFP announcement reads. To date, the financial impact includes global remediation costs estimated to be hundreds of millions of dollars. The investigation began in April 2026, after the AFP and FBI received key information from cybersecurity firms.

None of this required a clever zero-day. Borrowed trust in a maintainer account, a familiar package name and a helpful stranger in a chat channel were enough to reach a thousand organizations. It is part of why Vulpine keeps its dependency surface deliberately small and its trust model deliberately narrow - an account is a token shown once and stored only as a hash, so there is no password to reset and no email chain to hijack when the person on the other end of the conversation turns out to be the threat.

← All articles
Privacy Policy Terms © 2026 Vulpine. Your acts, your responsibility.