Two arrested in global supply-chain attack stealing 500K+ credentials

Two men from Western Australia have been charged over a global cybercrime operation that allegedly weaponized open-source software to steal credentials from more than 1,000 organisations worldwide. The Australian Federal Police (AFP), Western Australia Police Force, and the FBI executed search warrants in Perth on 26 August 2026, arresting a 21-year-old from Cottesloe and a 23-year-old from Mandurah. They now face 14 offences including unauthorised data modification and dealing with proceeds of crime.
How the attack unfolded
Investigators allege that the duo, linked to a syndicate known as TeamPCP, inserted malicious code into widely used open-source tools hosted on public repositories. Unsuspecting developers then integrated these compromised components into their own systems, unknowingly distributing the malware across government agencies, academic institutions, and private companies. The AFP stated that parallel investigations began in April 2026 after multiple cyber threat assessment companies alerted authorities to a growing pattern of malicious packages on open-source platforms states AFP.
Among the infected tools were Trivy, a container vulnerability scanner; KICS, an infrastructure-as-code analysis tool; LiteLLM, a library for routing AI model requests; and the Telnyx Python SDK—each commonly embedded in enterprise CI/CD pipelines, cloud workflows, and security processes. The scale of compromise is significant: over 500,000 credentials and at least 300 GB of data were exfiltrated, with remediation costs already running into the hundreds of millions of dollars.
A persistent threat to the software supply chain
This case underscores a troubling trend: attackers increasingly target the trusted tools that underpin modern software development. TeamPCP’s history reveals a pattern of supply-chain attacks, from earlier PyPI and NPM repository infiltrations to the recent “Mini Shai-Hulud” campaign, which even snared two OpenAI employees. By compromising widely adopted libraries, threat actors can achieve mass infiltration with minimal effort, turning a single malicious update into a backdoor for thousands of downstream users.
Why it matters
This incident is not an isolated anomaly but part of a broader shift in cybercrime strategy. The use of open-source repositories as attack vectors raises urgent questions about the security of the software supply chain—a foundation of digital infrastructure. For organisations, the lesson is clear: trust in open-source tools must be paired with rigorous validation, automated scanning, and rapid response protocols. For policymakers and platform maintainers, the challenge is to balance openness with security, ensuring that the very systems designed to accelerate innovation do not become the weakest link in the chain.
Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

