Security1 distinct publisher2 min readPublished
The AFP says a syndicate planted code in an open-source repository and harvested more than 500,000 credentials, with remediation running into the hundreds of millions, while the charge sheet names no package and no registry.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The weight in these charge sheets sits away from the code. Both men face four counts of unauthorised modification of data with intent to commit a serious offence, maximum five years, plus single counts of possessing and supplying data with intent, maximum three years each [10][11]. The 21-year-old from Cottesloe carries two more: dealing with proceeds of crime worth $100,000 or more, maximum 20 years, and failure to comply with a 3LA order, maximum 10 years [10]. On the AFP's own numbers, refusing to unlock a device is charged at twice the exposure of modifying the package. Eight counts for the 21-year-old and six for the 23-year-old make up the combined 14 the AFP announced [12].
Divide the estimates through and the per-victim picture is modest. More than 500,000 credentials spread across more than 1,000 organisations averages roughly 500 credentials per organisation [13]. At least 300GB across the same base is about 300MB each [14]. Read "hundreds of millions" at its lowest, $200 million, and the average remediation bill lands near $200,000 per organisation [15].
Detection came from outside the repository. The AFP says multiple cyber threat assessment companies passed information to it and the FBI in April 2026 [3], and warrants followed on 26 August, about four months later [16]. Whatever the syndicate published was in downstream builds well before that, and the credentials and authentication materials harvested through it [4] stay usable until each owner rotates them. An arrest does not expire a token.
All of this is police allegation, untested. Devices taken at Cottesloe, Hamilton Hill and Mandurah are still under forensic examination [8][18], and the value of the cryptocurrency payments police say the two received has not been established [9]. The AFP's own framing is the part to keep: a small number of trusted software components produced the global impact [19]. That is the familiar registry-trust finding, arriving this time with defendants listed in Perth Magistrates Court [2] and cryptocurrency-based money laundering in the allegation [7] instead of an advisory and a blog post.
Ranked by verification strength, evidence, and original report placement.
The AFP charged two West Australian men on 26 August 2026 with a combined total of 14 offences after executing search warrants in Perth with the Western Australia Police Force and the assistance of the FBI.
Parallel AFP and FBI investigations started in April 2026 after the two agencies received information from multiple cyber threat assessment companies regarding a syndicate that allegedly inserted malicious code into software available on an open-source repository, which was then unwittingly used by other developers.
Police allege infected software was distributed into computer systems at organisations across government, academia and the private sector, enabling the syndicate to infiltrate those organisations and steal or harvest sensitive data including user credentials and authentication materials.
The AFP and WAPF executed search warrants on 26 August 2026 at properties in Cottesloe, Hamilton Hill and Mandurah, arrested the two men, and seized electronic devices and other items for forensic analysis.
The Cottesloe man, 21, was charged with one count of possessing data with intent to commit a computer offence (max 3 years), four counts of unauthorised modification of data with intention to commit a serious offence (max 5 years), one count of supplying data with intent to commit a computer offence (max 3 years), one count of failing to comply with a 3LA order (max 10 years), and one count of dealing with proceeds of crime worth $100,000 or more (max 20 years).
The Mandurah man, 23, was charged with one count of possessing data with intent to commit a computer offence (max 3 years), four counts of unauthorised modification of data with intention to commit a serious offence (max 5 years), and one count of supplying data with intent to commit a computer offence (max 3 years).
Distinct publishers with included, body-backed reporting in this cluster.
Follow any of these and your For You feed starts watching them — no settings page required.
build
AFP charges two Perth men over poisoned packages police say reached 1000 organisations2 distinct publishers
product
Flare traced TeamPCP's GitHub handle to a HackerOne profile carrying a real name1 distinct publisher
security
AFP charges two men near Perth over the self-spreading worm behind the TeamPCP compromises1 distinct publisher
security
Malicious litellm PyPI releases tied to Trivy scan dependency bypassed official CI/CD1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Precise on the arrests, unverifiable on the harm
The release is strong exactly where the AFP has custody of the facts: suburbs, ages, statute subsections, maximum penalties, a court and a date, all checkable against the Perth Magistrates Court record. It is weakest where it matters most to everyone else. The 1,000 organisations, 500,000 credentials and 300GB arrive in one sentence with no method, no victim and no corroborating party, and the compromised software is never named. One issuer, no second account, charges untested.
One real enforcement action, an unauditable blast radius
Something concrete did happen on 26 August: warrants, arrests, devices seized, 14 charges, an FBI parallel investigation. That is real-world movement, not an announcement of intent. The claimed footprint behind it is another matter — 1,000-plus organisations with not one named, and no package for anybody to grep for, so the spread cannot be observed from outside the investigation. Forensics on the seized data is still running.
The lede outruns the estimate
The release opens by saying the syndicate allegedly set out to rob thousands of global businesses, then estimates more than a thousand organisations a few paragraphs later; 'significant global impact' and 'hundreds of millions' do similar work without a single named victim or component. The charges themselves are narrower and more concrete than the framing around them — possession, modification and supply of data, plus a proceeds count. This is announcement language, not fabrication, but the rhetorical range is wider than the evidence offered.
A disruption the announcing agencies own
Three agencies share the byline on a story about their own success, and the commander's quotes are about partnership and force multiplication rather than about the malware. Bigger stated impact makes for a bigger disruption. There is also a legal reason for the vagueness — matters are before the court, forensics is unfinished — which cuts against reading the missing package name as pure spin, though it leaves defenders in the same position either way. The private threat assessment firms credited with the referral are unnamed and get reputational benefit without exposure.
Confident about the prosecution, guarded about the numbers
We would stake a lot on the procedural spine — two men, 14 counts, those sections, that courtroom, that date — because an agency misstating its own charge sheet is rare and easily caught. We would stake little on the impact arithmetic, and we cannot check the technical claim at all. Single-issuer sourcing caps this: a second account from the firms that made the referral would move it quickly in either direction.