Security1 distinct publisher2 min readPublished
Australian police have two suspects, aged 21 and 23. Getting to them took no exotic tradecraft, and it does not undo the malicious package versions TeamPCP published across hundreds of open source tools.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Attribution here did not turn on tradecraft. @kernelstub, the X account of George Prepakis, an accomplished security researcher and self-described exploit developer, tweeted a public invite link to a Matrix server he created and named Cybercats, and TeamPCP plus several other cybercrime entities have used it to talk daily for the past several months [12][13]. Austin Larsen of the Google Threat Intelligence Group describes the group as a peer community of individually-skilled actors with one clear center of gravity, not a structured crew under a single operator [11]. A public invite link is how an outsider indexes a peer community.
KrebsOnSecurity says it learned the 21-year-old suspect's real identity in June and has been in contact with him since [14]. The report carrying the AFP statement is published under an August 2026 URL [16], which puts roughly two months between a reporter holding the name and police announcing the arrests [17]. The AFP named neither defendant [2], so nothing on the public record connects Prepakis to either arrest. Krebs also says the story examines clues left behind by the TeamPCP leader that likely led to his undoing, and includes interviews with the group's self-described spokesperson [15]. The arrests, the ages and the AFP's own characterisation are on the record [1]; the structural reporting on Cybercats and the leader comes from a single publisher [19].
The code is what the arrests leave untouched. Shai-Hulud spread by publishing malicious versions of packages whose maintainer credentials had been phished or stolen [4]. In March the group compromised LiteLLM, an open source AI gateway fronting more than 100 large language models [8], and CloudSEK's analysis put the take at cloud service keys and other secrets from more than 2,500 organizations [9]. In May TeamPCP claimed at least 3,800 GitHub repositories after one GitHub developer installed a compromised code extension [10]. Andy Greenberg's account in Wired explains why those counts compound: stolen credentials publish the next poisoned tool, that tool lands on the machine of a developer who maintains another one, and the collection of breached networks grows [5]. From late 2025 to the August announcement, that is about nine months of the cycle running [18].
Every secret that transited a compromised build in that window stays valid until someone rotates it. That work is indexed by package version and publish date.
Ranked by verification strength, evidence, and original report placement.
The Australian Federal Police said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses."
The AFP statement was released the day of the KrebsOnSecurity report and the AFP did not name the defendants.
TeamPCP is blamed for the longest running spree of software supply chain attacks ever; it emerged in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit.
Members of the group compromised corporate cloud environments using a self-propagating worm dubbed Shai-Hulud, which added malicious code to open source programs maintained by developers whose credentials at GitHub or NPM were phished or stolen.
Wired journalist Andy Greenberg described the core tactic in May as cyclical: hackers plant malware in a commonly used open source tool, the malware steals credentials from other developers' machines, those credentials let them publish malicious versions of further development tools, and the cycle repeats as the collection of breached networks grows.
A recent analysis by security firm CloudSEK found the LiteLLM attack harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world's top technology companies.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-publisher
The reporting is specific and well-attributed within itself: an official AFP quotation, named third-party analysts (Austin Larsen of Google Threat Intelligence Group), quoted vendor analyses (Dataminr, CloudSEK), a quoted Wired description of the tradecraft, and the outlet's own months-long contact with a suspect. What holds the score down is structural: both supplied records are the same article, so nothing in the cluster is independently corroborated, and two of the biggest numbers are second-hand (CloudSEK's 2,500 organizations, relayed without methodology) or attacker-sourced (the 3,800 repositories claimed by the group itself). The identification of a named individual as the community's center of gravity rests solely on the outlet's investigation, while the police statement it sits beside names no one.
Broad, quantified real-world impact
Read as real-world footprint rather than product uptake, the evidence of impact is substantial and dated: a March compromise of a widely used AI gateway that reportedly yielded cloud keys from more than 2,500 organizations, a May incident with at least 3,800 GitHub repositories claimed, malicious code embedded in hundreds of open source tools since late 2025, a publicly released third-generation worm codebase with an active contest driving further attacks, and a daily-use coordination server shared with other criminal groups. The score is not higher because the two headline counts carry vendor and attacker provenance respectively, and because no source describes remediation status, so the persistence of exposure is asserted rather than measured.
Mildly overstated framing over solid facts
The underlying facts are largely sober and the cluster's own dek is notably deflationary - it stresses that no exotic tradecraft was needed and that arrests do not undo published malicious package versions. The positive tilt comes from framing rather than fabrication: the unquantified superlative 'longest running spree of software supply chain attacks ever', an arrest headline paired with an attribution to a specific named leader whom the quoted police statement does not name, and repetition of an attacker's self-reported 3,800-repository count alongside a vendor figure without methodology. Set against that, the story understates the operational consequence it raises but never resolves - whether malicious versions remain installable - so the net overstatement is small.
Multiple documented incentive distortions
Incentives are unusually explicit here and pull in several directions. The attackers built a payout structure that rewards compromising the highest-download libraries and, per Dataminr, treated the $1,000 Monero prize as a recruitment floor to buy 'all meaningful access' from entrants - an incentive to inflate and publicize scale. Both quantified impact claims come from commercial security firms whose analyses double as marketing (CloudSEK on 2,500 organizations, Dataminr on the contest). The AFP has an institutional interest in announcing a syndicate takedown, describing the operation in sweeping terms while naming no defendants. And the reporting outlet holds an exclusive - months of private contact with a suspect and an identification no one else has - which is a scoop incentive to lead with attribution. None of this makes the claims wrong, but each load-bearing number reaches the reader through an interested party.
Core event solid, attribution less so
Confidence splits cleanly. That an arrest announcement occurred, with two Western Australian men aged 21 and 23, is directly quoted from the AFP and is reliable, as are the dated, internally consistent descriptions of Shai-Hulud's mechanics, the contest rules, and the LiteLLM and GitHub incidents. Confidence is materially lower on the numbers and the naming: one publisher, duplicated twice in the cluster, carries all of it; the impact counts are vendor- and attacker-sourced; the leader identification is uncorroborated by any legal filing in evidence; and remediation status is entirely absent, so the story's most consequential open question cannot be scored at all.
security
Perth charges leave the TeamPCP rotation list exactly where the FBI left it on July 22 distinct publishers
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
build
56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet1 distinct publisher
security
WSL is a working bridge, and npm hygiene stops at the container wall1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 27, 2026