Security1 publisher2 min readPublished
AFP, FBI and Western Australia Police arrest two men over the TeamPCP npm attacks
Aikido says the pair, both in their early 20s, ran TeamPCP's npm supply chain campaigns with a worm they cloned from Shai-Hulud. Whoever wrote the original is still unidentified, and the code is still published.
The Watch · Security desk
What happened
- The Australian Federal Police, the FBI and the Western Australia Police Force say they have arrested two men in their early 20s who they allege were behind the TeamPCP npm supply chain attacks.
- Aikido says TeamPCP cloned the Shai-Hulud worm and shows no sign of having run the original S1ngularity and Shai-Hulud campaigns of summer 2025, despite reporting that credited the group with both.
- Aikido puts significant damage and disruption to companies and individuals on the past six months of supply chain attacks, with TeamPCP's barrage singled out as the worst of it.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction Because reporting had pinned the Shai-Hulud waves on TeamPCP, these arrests will be read in some shops as the end of that campaign; Aikido separates the two, which leaves the worm's authors untouched by the case.
- constraint On Aikido's own numbers, a campaign takes hours or days to stand up and a cross-border case takes months or years, so an arrest lands well after the exposure window it answers to has closed.
- precedent A worm already cloned once by a group with no special skill is cheap to clone again, so the defensive work on npm publish tokens has to be priced as recurring, not as incident response.
What's public so far is an announcement, not a charge sheet. Aikido's write-up gives the three forces and the ages, and does not carry names, counts, custody status, or the list of npm packages the allegation covers [1]. Anyone hoping to reconcile their own token rotation against a suspect list has nothing to reconcile against yet.
The interval matters more. The original S1ngularity and Shai-Hulud attacks ran in the summer of 2025, and Aikido says there is no indication TeamPCP were behind them; the group cloned that worm [2]. The earliest date the announcement can carry is March 21, 2026, because the post refers back to that day as the one on which its author, mid-investigation, found the group had turned its attention to him [5]. Take the generous end of summer 2025, late September, and the people who wrote the worm have gone unattributed for at least six months while a second crew ran their code [1]. Aikido says we may never know who they were [4].
That is the load-bearing fact for anyone reading these arrests as deterrence. Two crews are known to have used this worm. Only one of them has anyone in custody [2].
The rest follows from what Aikido says made TeamPCP effective: speed, not depth, the speed with which they turned public exploits and research, plus malware ideas already published elsewhere, into live campaigns, with LLMs closing the gap between seeing a technique and running it at scale [6][7]. The LLM part is Aikido's inference from watching the group's output, not something the police announcement establishes. The input side of that pipeline does not change when two operators are removed from it. Every technique the group used is still published, and so is the worm they copied.
Aikido's read on the actor is worth keeping for the next one: neither state-backed nor conventional organised crime, mixing money, politics, disruption, ego and attention-seeking [11]. The damage the company attributes to six months of that activity came from people it describes as unsophisticated [10][6]. The skill floor for repeating it is where it was, and Aikido expects another group like this [12].
What to watch
- The AFP or WAPF charge sheet: names, counts, and which npm packages the case actually covers.
- Whether a third group publishes a fresh clone of the worm now that TeamPCP's alleged operators are in custody.
- Any attribution of the summer 2025 S1ngularity and Shai-Hulud operators, who remain unidentified.