Australian Federal Police charged two Western Australian men, aged 21 and 23, as the alleged leaders of TeamPCP, with 14 charges between them. The AFP alleges the group’s supply-chain campaign hit more than 1,000 organisations, stole over 500,000 credentials and exfiltrated more than 300GB of data, with remediation costs running into the hundreds of millions of dollars. TeamPCP published its Mini Shai-Hulud worm framework on GitHub under an MIT licence in May, and a near-identical npm attack on 4 August has been claimed by nobody. The arrests settle accountability for one crew; the tooling is still sitting in public.
TeamPCP put its worm framework on GitHub under an MIT licence on 12 May 2026, as The Register reported at the time. That was 107 days ago. Yesterday the AFP arrested two men in Cottesloe and Mandurah, Western Australia, and charged them as the group’s alleged leaders. Only one of those two events is reversible, and it isn’t the licence.
AFP charges: 14 counts across two men in their early twenties
The AFP media release puts eight charges on the 21-year-old from Cottesloe and six on the 23-year-old from Mandurah. Both appeared in Perth Magistrates Court today. ABC News reports the younger man was denied bail over concerns he would tamper with evidence, and the older man was remanded in custody with a next appearance on 18 September. The Record puts the combined maximum sentences at 82 years.
The alleged damage: 1,000-plus organisations compromised, 500,000-plus credentials stolen, 300GB-plus of data exfiltrated, and remediation costs in the hundreds of millions of dollars. ABC reports a higher figure of 100 terabytes extracted, which doesn’t appear in the AFP release. BleepingComputer’s victim list includes Telnyx, SAP, TanStack, Mistral AI, OpenAI, GitHub and the European Commission, whose April breach was publicly attributed to the group.
Coverage disagrees on which man is which. The per-suspect breakdown in The Hacker News’ account contradicts the AFP’s own release and The Record’s reporting, so treat any name-to-suburb-to-charge-count mapping you read as unsettled. Full legal names have circulated via Brian Krebs, who traced the aliases Ellis, @pcpcats and BulkDMT through his own investigation and interviewed one of the suspects over Signal before the arrests. The AFP withheld names, standard practice for Australian charge reporting.
156 days from first compromise to arrest
The first confirmed TeamPCP compromises of security tooling landed on 23 March 2026: the Checkmarx KICS GitHub Action and Trivy. Two days earlier, Aikido researcher Charlie Eriksen was personally targeted by the group while investigating it. The AFP, FBI and WA Police opened their joint investigation in April, prompted by tips from security firms.
The FBI’s FLASH alert naming TeamPCP and detailing its credential-theft methods came out on 2 July, 101 days after the first confirmed compromise and 56 days ago. The arrests came 156 days after that first compromise. By the standards of transnational cybercrime investigation, five months is quick. By the standards of a worm propagating through npm, it is an epoch.
The keyv and cacheable wave nobody has claimed
On 4 August, 23 days ago, the GitHub account of keyv and cacheable maintainer Jared Wray was taken over, and malicious versions of keyv, cache-manager and related npm packages went out. Chainguard’s writeup identifies the same Mini Shai-Hulud toolkit, and states plainly that no actor has claimed responsibility.
That gap matters for how you read yesterday’s news. If the August wave was TeamPCP, the group stayed operational until three weeks before the arrests. If it was somebody else picking up an MIT-licensed worm framework, the arrests removed two people from a problem that has already replicated past them. Nobody has confirmed which, and Chainguard declines to guess. Oligo Security’s tracing of TeamPCP-linked infrastructure back to 2020, overlapping with actors tracked as TA-NATALSTATUS and IronErn, suggests the boundaries of this crew were fuzzy well before August.
”Highly organised” versus “not especially sophisticated”
The AFP called the operation internationally significant, and the FBI’s language runs the same direction. Eriksen, who spent months tracking the group and got targeted for it, describes them differently: neither state-backed, nor a mature criminal enterprise, nor purely ideological, and “not especially sophisticated.”
Both descriptions can hold at once. The impact was enormous; the capability required to produce it was apparently modest. That is Eriksen’s real argument, and it’s the uncomfortable one:
“the conditions that made TeamPCP possible are not going away. They are getting worse.”
His reasoning: LLM-assisted tooling compresses campaign development into hours or days, while a law enforcement investigation takes months or years. The 156-day figure above is the optimistic case, involving three agencies across two countries plus tips from industry.
The structural weaknesses TeamPCP exploited are unchanged this morning. Maintainer accounts on npm and PyPI still fall to phishing. A compromised GitHub Action still executes with whatever secrets the workflow hands it. Package publication still rests on a single credential in most repositories. Two arrests in Perth leave all of that where it was, and the AFP has not claimed otherwise.
Sources: AFP media release • ABC News • Krebs on Security • Aikido Security • Chainguard
Coverage: The Record • BleepingComputer • The Register • The Hacker News • SecurityAffairs
Related on this blog: [AUTO] Supply Chain Attacks Adapt Faster Than Defenses • [AUTO] Security Tools as First-Strike Targets • [AUTO] A Frontier Model Defended Its Own Malicious Code