Australian Police Charge Two TeamPCP Suspects After Open-Source Supply Chain Attacks
Australian Federal Police say two men in Western Australia have been charged after a joint AFP, FBI and Western Australia Police Force investigation into an alleged cybercrime syndicate tied to malicious open-source software.
The AFP said the men were arrested on August 26 after searches in Cottesloe, Hamilton Hill and Mandurah. They face a combined 14 offences, including alleged data intrusion, identity crime, unauthorized data modification, cryptocurrency-based money laundering and failure to comply with an access order.
Police allege the syndicate inserted malicious code into software available through an open-source repository, which was then used by developers across government, academia and the private sector. The AFP estimated that the campaign potentially compromised more than 1,000 organizations globally, enabling the theft of more than 500,000 credentials and at least 300 gigabytes of data.
TechCrunch reported that the arrests relate to TeamPCP, a group linked earlier this year to attacks on developer tools and open-source projects used by AI and cloud companies. Earlier TeamPCP-linked incidents affected LiteLLM, Mercor and software paths that exposed access to companies including OpenAI, according to previous reporting.
The charges do not prove guilt, and Australian authorities have not named the defendants. The case is still significant for AI infrastructure teams because it moves one of 2026's most disruptive software supply chain campaigns from incident response into criminal prosecution.