AFP-FBI-WAPF disrupt TeamPCP: two Western Australia men charged over the npm/GitHub supply-chain worm operation AFP estimates compromised 1,000+ organisations, 500,000+ credentials and 300+ GB of data
The first law-enforcement disruption of the Shai-Hulud npm-worm operator, with AFP's own scale estimate now on the public record
Analysis
The Australian Federal Police, FBI and Western Australia Police Force jointly announced on 2026-08-27 that two Western Australian men, aged 21 and 23, were charged with a combined 14 Commonwealth cybercrime offences (unauthorised data modification with intent to commit a serious offence, supplying data with intent to commit a computer offence, dealing with proceeds of crime over AUD 100,000, and, for one defendant, failing to comply with a section 3LA data-access order) following parallel AFP/FBI investigations that began in April 2026 after multiple threat-intelligence vendors reported a supply-chain-poisoning syndicate.
AFP states the syndicate "allegedly inserted malicious code into software available on an open-source repository, which was then unwittingly used by other developers," with infected software subsequently distributed into "computer systems at other organisations across government, academia and the private sector," enabling theft of user credentials and authentication material. AFP's own estimate: "it is estimated the malicious code potentially compromised more than 1000 organisations globally, enabling the theft of more than 500,000 credentials, and the exfiltration of at least 300 gigabytes of data" (Australian Federal Police, 2026-08-27), with remediation costs in the hundreds of millions of dollars. FBI Cyber Division names the group directly: "these men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide" (FBI Cyber Division Assistant Director Brett E. Leatherman, 2026-08-27).
KrebsOnSecurity, which had independently identified one of the defendants, the group's self-described spokesperson, in June and interviewed him extensively via Signal, corroborates and adds operational-model detail: TeamPCP's core tactic is cyclical, compromising a developer's credentials to insert malicious code into a widely-depended-upon open-source package, harvesting the credentials of downstream developers who install it, and repeating against the next package, powered principally by the self-propagating "Shai-Hulud" worm (three iterations to date, whose source TeamPCP itself open-sourced). Prior TeamPCP campaigns already tracked by named security vendors include the March 2026 compromise of the LiteLLM open-source AI gateway (CloudSEK: 2,500+ organisations' cloud-service keys and CI/CD secrets harvested) and a May 2026 claim of roughly 3,800 compromised GitHub repositories.
Google's Threat Intelligence Group characterises TeamPCP's structure directly: "it is not a structured criminal crew with a single operator. It is a peer community of individually-skilled actors, with one clear center of gravity" (Austin Larsen, Google Threat Intelligence Group, via KrebsOnSecurity, 2026-08-27), tracing its likely primary operator's residential/mobile internet connections to South Africa during at least some of its attacks. Investigators note further arrests are not ruled out; both defendants were held in custody pending an 18 September court date.
This is TeamPCP's first law-enforcement disruption. It does not change the remediation guidance already published for the LiteLLM/Trivy and coding-agent CI-harness campaigns attributed to the same actor; a decentralised peer community losing two participants does not retire the worm's self-propagating infrastructure or the copycat variants it has already spawned; the standing guidance on pinning dependencies and auditing for Shai-Hulud-family indicators still applies.
Cited evidence
It is estimated the malicious code potentially compromised more than 1000 organisations globally, enabling the theft of more than 500,000 credentials, and the exfiltration of at least 300 gigabytes of data.
These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide.
It is not a structured criminal crew with a single operator. It is a peer community of individually-skilled actors, with one clear center of gravity.
Sources2
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.