Australian authorities arrested two men on Wednesday, accusing them of involvement in TeamPCP, a hacking group linked to a nine-month supply-chain attack spree that compromised more than 1,000 organizations worldwide.
The Australian Federal Police charged the men with 14 offenses and identified their residences as Cottesloe and Mandurah in Western Australia. While the agency did not release their names, KrebsOnSecurity published a detailed investigation naming both defendants and outlining the missteps that led to their arrests.
TeamPCP first emerged in December, drawing attention for infecting open-source software through CI/CD pipelines. The malware spread virally by embedding itself into software packages, creating a persistent chain of compromises that frustrated global law enforcement and security teams.


