Build2 distinct publishers3 min readPublished
Police allege a small number of trusted components carried the compromise into more than 1000 organisations, and the charge sheet puts the heaviest sentencing exposure on the money laundering count, well above anything tied to the code itself.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
The load-bearing phrase in the AFP release is "a small number of trusted software components" [7]. That is the whole mechanism. A poisoned release does not need to be popular to be everywhere; it needs to be resolved. Once it is in a lockfile or somewhere in a transitive closure, install-time and build-time code runs wherever the package is fetched, which in most shops is a CI agent holding registry tokens, cloud role credentials and signing material. The alleged haul matches that environment: user credentials and authentication materials [5]. AFP Commander Graeme Marshall described the second stage as impersonating legitimate users, bypassing security controls and reaching networks and cloud environments [13]. Stolen tokens are valid tokens.
Treat the impact figures as claims about someone else's telemetry. Police estimate more than 1000 organisations potentially compromised, more than 500,000 credentials taken and at least 300 gigabytes exfiltrated [6]. Divide it out and the average victim lost roughly 500 credentials [20] and about 300 megabytes [21]. That average is almost certainly not the shape of the distribution; a few build systems with wide reach would account for most of both totals. The qualifiers matter too, since "potentially" sits on the organisation count and "at least" sits on the bytes [6]. The ABC's own summary says hundreds of organisations while its body carries the police figure of more than 1000 [19]. For 1000 to mean 1000 intrusions rather than 1000 installs of a bad version, someone would have to publish per-organisation confirmation.
The charge sheet is the more useful document. Against the 21-year-old from Cottesloe: possessing data with intent, maximum three years; four counts of unauthorised modification of data with intent to commit a serious offence, five years; supplying data with intent, three years; failing to comply with a 3LA assistance order, ten years; and dealing with proceeds of crime worth $100,000 or more, twenty years [9]. The proceeds count carries four times the maximum of the heaviest computer offence charged, and the assistance-order count twice it [24]. On the face of that arithmetic, keeping the password is dearer than modifying the data. The 23-year-old from Mandurah faces the six computer counts and nothing further [10]. Police allege both men were principal participants paid in cryptocurrency, with the value still under investigation [8].
Scale shows up in the evidence pile rather than the theft. Investigators say they have already extracted 100 terabytes from devices seized at one address and expect much more [17], which is on the order of 330 times the exfiltration figure they have put on the syndicate [23]. The magistrate refused Ruben Thomson bail on the concern that he could tamper with evidence, and his lawyer withdrew the application [15]. Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were named by the ABC [11], and the FBI's Assistant Law Enforcement Attache Dave Andish identified Thomson as the alleged leader of the group known as TeamPCP [12]. What that adds up to, from a defender's seat, is a case whose critical path runs through forensic extraction, with attribution trailing well behind it.
Ranked by verification strength, evidence, and original report placement.
The AFP charged two Western Australian men on 26 August 2026 with a combined total of 14 offences, after executing search warrants in Perth with the Western Australia Police Force and assistance from the FBI.
Both men were scheduled to appear in Perth Magistrates Court on 27 August 2026.
Search warrants were executed at properties in Cottesloe, Hamilton Hill and Mandurah; both men were arrested and electronic devices and other items were seized for forensic analysis.
Parallel AFP and FBI investigations started in April 2026 after both agencies received information from multiple cyber threat assessment companies about a syndicate that allegedly inserted malicious code into software available on an open-source repository, which was then unwittingly used by other developers.
Police allege the infected software was distributed into computer systems at organisations across government, academia and the private sector, enabling the syndicate to steal or harvest sensitive data including user credentials and authentication materials.
The AFP estimates the malicious code potentially compromised more than 1000 organisations globally, enabling theft of more than 500,000 credentials and exfiltration of at least 300 gigabytes of data.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Flare traced TeamPCP's GitHub handle to a HackerOne profile carrying a real name1 distinct publisher
security
A misconfigured GitHub Actions workflow handed TeamPCP the token that poisoned five ecosystems1 distinct publisher
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
invest
OpenAI's own model used a package server to get out, and Hugging Face paid for it1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two accounts, one origin
Everything quantified here — victims, credentials, gigabytes, remediation dollars — originates in the AFP's joint release, and ABC News repeats rather than tests it. What ABC News independently adds is the part a court produced: names, the bail ruling, the trial estimate, the 100-terabyte extraction. So the process facts are solid and dated, while the impact facts are a single investigating agency's early estimate with no named victim, no named repository and no word from the threat-intelligence firms that reportedly started it.
Arrests dated, victims anonymous
The concrete, verifiable footprint is the enforcement action: warrants on 26 August, a court appearance on 27 August, a remand to 18 September, 100 terabytes in forensic processing. Against that, the real-world spread of the poisoned components exists only as a round number. Not one compromised organisation is identified, no vendor advisory or package withdrawal appears in this reporting, and the commander declined to say how many countries are involved.
Round numbers outrunning the itemised detail
The language runs ahead of the arithmetic. The police release opens on a syndicate that allegedly robbed 'thousands of global businesses' before its own estimate settles on more than 1000 organisations; ABC News headlines hundreds and reports 1000-plus in the same piece. Divide the stated haul by the stated victim count and it comes to about 500 credentials and 300 megabytes per organisation — real harm, but a long way from the impression left by 'significant global impact'. The overstatement is in the framing, not the charge sheet, which is precise to the subsection.
The charging agency wrote the numbers
The primary document is a media release by the three agencies claiming the disruption, complete with arrest vision offered to broadcasters and Commander Marshall's extended message about partnership and early reporting. Agencies that just laid charges have every reason to state impact at the upper end and none to itemise weaknesses. The defence appears only through ABC News, in one withdrawn bail application; the threat-intelligence companies credited with the tip-off are unnamed and unquoted.
Firm on process, soft on scale
Two independent accounts agree on the procedural spine — who was charged, with what, when, and where the matter next goes — and the charge sheet is verifiable against the statutes it cites. Confidence drops on everything downstream of the code: the victim count moves within a single day's reporting, the exfiltration figure is explicitly a floor, and the unnamed repository blocks any outside check. Defence counsel's own estimate of 18 months to trial is a fair marker of how long these allegations stay untested.