Security1 distinct publisher2 min readPublished
Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Each stolen token was both loot and transport. The worm used harvested npm and GitHub credentials to publish tampered packages and modify repositories, which delivered it into the next developer environment [5]. That loop has one throttle a defender actually owns, and it is how long a token stays valid.
Shai-Hulud surfaced publicly in late 2025, against corporate cloud environments [4]. The one window with hard public numbers came later. CloudSEK data analyzed by StepSecurity, cited by Suzu Labs' Jacob Krell, counted 78,330 secrets pulled from the CI/CD pipelines of 2,186 organizations over five days in March, including public companies with a combined market capitalization above $6 trillion [7]. Work the arithmetic: about 15,700 secrets a day [1], and roughly 36 per victim organization [2]. Set against the AFP's 500,000-plus, that single five-day stretch accounts for around 16 percent of the syndicate's entire alleged credential take [3]. Either the police figure is a floor assembled from confirmed cases, or March ran hotter than the rest of the campaign. Both readings land on the same control.
The distribution model is why the tooling outlives the defendants. According to Krell, TeamPCP did not gate access through an affiliate structure the way ransomware crews do. It released Shai-Hulud as open-source attack tooling and crowdsourced deployment through a paid contest [8]. Krell also points to KrebsOnSecurity's description of the group's activity as the longest-running spree of software supply chain attacks on record [11]. Public code with a documented technique and a proven yield can keep working long after its authors are gone.
That number reads as an inventory of exposure, tallying what sat exposed long enough to be scanned, rather than a running scoreboard of victims. More than 500,000 credentials [2] measures how many npm tokens, GitHub credentials and cloud provider secrets sat in developer environments and build configs long enough for a scanner the attackers pointed at them to find [5]. Each one that had already expired blocked a propagation step before it could happen. Token lifetime is the only variable in that equation that the victim sets.
Ranked by verification strength, evidence, and original report placement.
Australian law enforcement officials, working with the U.S. Federal Bureau of Investigation, arrested two men on Wednesday on cybercrime charges; the men allegedly are members of a global cybercrime syndicate, TeamPCP, suspected of creating the Shai-Hulud worm.
The Australian Federal Police said TeamPCP is estimated to have enabled the theft of more than 500,000 credentials and at least 300GB of data.
The AFP said the financial impact of the gang's activities includes global remediation costs in the hundreds of millions of dollars.
TeamPCP made headlines in late 2025 when it began compromising corporate cloud environments with the self-propagating Shai-Hulud worm, which stole credentials from developers working on projects using repositories such as GitHub and npm.
ReversingLabs researchers documented Shai-Hulud in 2025, finding it systematically harvested npm tokens, GitHub credentials and cloud provider secrets from compromised developer environments using tools such as TruffleHog, then leveraged those credentials to tamper with additional packages and repositories, turning the software supply chain into a propagation mechanism.
Jacob Krell of Suzu Labs said the joint AFP-FBI investigation began in April after cybersecurity companies provided key information, and arrests followed months later.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
AFP charges two Perth men over poisoned packages police say reached 1000 organisations2 distinct publishers
product
Flare traced TeamPCP's GitHub handle to a HackerOne profile carrying a real name1 distinct publisher
build
56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet1 distinct publisher
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor's account, borrowed numbers
A single publisher carries this story, and it is the firm whose own researchers first documented the worm. The police estimate and Commander Marshall's statement are on the record and attributable. The most repeated figure is not: 78,330 secrets from 2,186 organisations travels from CloudSEK telemetry, through StepSecurity's analysis, into a Suzu Labs executive's quote, with nothing linked and no year attached to the March it describes. Even the superlative is second-hand — ReversingLabs quoting a commentator quoting KrebsOnSecurity.
Wide blast radius, uneven counting
The footprint is more checkable than the arithmetic. Forty-two malicious @tanstack/* releases went to npm after publishing credentials were stolen, one of them a router pulled more than 12 million times a week, with 160-odd packages hit in the May resurgence. Add two national agencies executing arrests and this is a phenomenon with consequences on the ground, whatever the credential total settles at. What is thin is per-victim documentation: 2,186 organisations are counted but none are named.
Scale talk ahead of the paper trail
Nothing here looks invented; the numbers are simply stacked in a way that flatters. Divide 78,330 by five days and you get roughly 15,700 secrets a day, a rate that only means something if the telemetry chain behind it holds — and the post does not link it. Set the same 78,330 against the AFP's 500,000 and five days appear to account for a sixth of the entire spree, except pipeline "secrets" and police-counted "credentials" are not established as the same unit by anyone quoted. The arrests and the police estimate need no inflation; the surrounding superlatives supply it anyway.
Supply-chain vendor on supply-chain crime
This is a software supply chain security company's account of software supply chain crime, and it opens with a 14-day free trial button and a second pitch for the same firm's community product. Nearly every voice quoted is an executive at a company selling adjacent tooling — ThreatLocker, Optiv, Suzu Labs, Black Duck — and the worm's original research is ReversingLabs' own. That does not make any of it wrong. It does mean the two things this reporting emphasises hardest, the sheer scale and the vulnerability of scanners inside build pipelines, are also the two things the assembled room sells against.
Single account, fuzzy calendar
A second, independent account would move this a long way. The arrests and the police sizing are firm; the timeline is not — "late 2025", then a March and a May with no years attached, and no charge sheet, defendant names or court date to anchor any of it. The one question a reader actually wants answered, whether taking two people off the board slows the group, is left standing as a disagreement between two quoted practitioners.