Australian law enforcement has arrested two men in Perth on Thursday in connection with widespread cyberattacks attributed to TeamPCP, a hacking group accused of targeting open-source software and compromising high-profile companies. The pair face charges spanning hacking, money laundering, and other cybercrime offenses, with court proceedings expected later in the day. Authorities say the breach involved more than a dozen distinct offenses.
The Australian Federal Police (AFP) stated the suspects are believed to have infected popular open-source projects to distribute malicious code. The infiltrations allegedly enabled theft of private keys, credentials, and sensitive data, which was later used for extortion. An FBI cyber division official claimed TeamPCP may have infiltrated upwards of 1,000 organizations.
Scope & Nature of the Attacks
The group allegedly corrupted a vulnerability scanner called Trivy, affecting anyone dependent on that tool — a list that includes Mercor, LiteLLM, and OpenAI, among others. TeamPCP is accused of modifying open-source components so that victims were led to unwittingly install backdoors. Once inside, the attackers reportedly harvested credentials, including those used to access cloud storage and development infrastructure.
Other alleged targets spread across both public and private sectors; accusations include the targeting of the European Commission’s cloud systems and well-known developer platforms like GitHub. These actions are consistent with earlier hacking campaigns where supply chains are weaponized to gain network-wide access. Also concerning: investigators claim over half a million credentials were stolen in pursuit of expanding the intrusion.
Investigation & Identification
Investigations kicked off in April 2026 after threats and intelligence were shared by private cybersecurity firms. While the AFP has not formally named the suspects, independent reporting identifies one alleged hacker as Ruben Thomson, alias “Ellis,” who reportedly claimed leadership of TeamPCP until March 2026.
Law enforcement said the arrests involved seizure of significant amounts of stolen data, computer equipment, and electronics. Victims of the breaches are expected to be notified. There’s no word yet on whether extradition requests may be pursued.
TeamPCP is already known for targeting the software supply chain: compromising widely-used open-source tools to inject malicious code. These actions exploit a critical vulnerability vector in modern software development, where trust in upstream dependencies and open-source libraries is assumed.
The consequences of this case could ripple far beyond Australia. As attack vectors via supply chains proliferate, businesses will need to invest more heavily in upstream security—code auditing, dependency scanning, and closer monitoring of third-party modules are now non-negotiable. What remains to be seen is how international collaboration will play out in holding such actors to account—and whether this arrest signals a turning point in fighting supply chain–based cybercrime.