Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two men (aged 21 and 23) from Western Australia were arrested by the AFP in connection with TeamPCP, a cybercrime syndicate behind the longest-running software supply chain attack spree on record TeamPCP operates through a decentralized peer community centered around George Prepakis (@kernelstub) and his "Cybercats" Matrix chat server, rather than as a traditional hierarchical criminal organization Their self-propagating worm Shai-Hulud compromises open-source tools by targeting developers' stol
Analysis
TL;DR
- Two men (aged 21 and 23) from Western Australia were arrested by the AFP in connection with TeamPCP, a cybercrime syndicate behind the longest-running software supply chain attack spree on record
- TeamPCP operates through a decentralized peer community centered around George Prepakis (@kernelstub) and his "Cybercats" Matrix chat server, rather than as a traditional hierarchical criminal organization
- Their self-propagating worm Shai-Hulud compromises open-source tools by targeting developers' stolen or phished credentials at GitHub and NPM, creating a cyclical exploitation chain that grows their breached network
- In March 2026, TeamPCP compromised LiteLLM, an open-source AI gateway connecting users to 100+ LLMs, harvesting cloud service keys and secrets from over 2,500 organizations including major tech companies
- The group has run recruitment contests offering Monero prizes to participants who conduct the largest supply chain operations, using the competitions to identify talent and acquire malicious access at scale
Why It Matters
This represents a paradigm shift in how cybercriminal organizations operate—moving from structured crews to decentralized peer communities that collaborate across traditional group boundaries, making attribution and disruption significantly harder. The targeting of AI infrastructure through compromised open-source gateways like LiteLLM signals that the AI supply chain is now a primary attack surface, directly threatening the security of enterprise AI deployments worldwide.
Technical Details
- Shai-Hulud Worm: A self-propagating malware that compromises open-source packages by targeting developers whose GitHub/NPM credentials were phished or stolen, then planting malicious code that harvests credentials from other developers' machines, creating a recursive supply chain attack cycle
- LiteLLM Compromise: TeamPCP injected malicious code into LiteLLM, an open-source AI gateway proxy, which harvested cloud service keys and secrets from over 2,500 organizations, demonstrating how AI infrastructure tooling has become a high-value attack vector
- GitHub Extension Attack: In May 2026, a compromised GitHub code extension led to the compromise of at least 3,800 code repositories, showing how IDE-level tooling can serve as a distribution vector
- Contest-Based Recruitment Model: TeamPCP published Shai-Hulud v3 source code and ran a competition scoring participants by weekly/monthly download counts of compromised packages, with a $1,000 XMR floor prize and promises of higher payouts for valuable access
- Cybercats Coordination Infrastructure: A public Matrix chat server operated by George Prepakis serves as the communication hub where multiple threat actor groups coordinate, share capabilities, and recruit, blurring traditional organizational boundaries
Industry Insight
- Organizations relying on open-source AI tooling should implement strict supply chain security practices including SBOM verification, code signing validation, and monitoring of package integrity—especially for gateway/proxy software that sits between applications and LLM APIs
- The decentralized "peer community" model of modern cybercrime means traditional takedown strategies targeting a single organization will be insufficient; industry-wide threat intelligence sharing and coordinated defense across the open-source ecosystem is essential
- The contest-based recruitment approach demonstrates how threat actors are gamifying cybercrime to lower barriers to entry and scale operations—security teams should monitor public hacker forums and social media for signs of similar competitive campaigns that could indicate emerging supply chain threats
Disclaimer: The above content is generated by AI and is for reference only.