Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Australian Police Arrest Two Men Accused of Running TeamPCP Hacking Group Behind Shai-Hulud Worm

Australian authorities arrested two men in Western Australia on Wednesday, August 26, over their alleged roles in TeamPCP, the cybercrime group blamed for one of the longest-running software supply-chain attack campaigns on record.
The Australian Federal Police, working with the FBI and Western Australia Police Force, charged a 21-year-old from Cottesloe with eight offenses and a 23-year-old from Mandurah with six, according to a statement from the AFP and reporting from Help Net Security. The charges include unauthorized modification of data, possessing and supplying data for computer offenses, dealing with proceeds of crime worth $100,000 or more, and failing to comply with a court order to hand over device passwords. Maximum penalties range from three to 20 years in prison depending on the charge.
Australian police did not name the suspects. Australian media, and independent cybersecurity journalist Brian Krebs of KrebsOnSecurity, identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Krebs reported he learned Thomson's identity back in June and had been in direct contact with him since, communicating with someone he says was TeamPCP's self-described spokesperson and, by his own account, the group's leader until March 2026.
The two are due back in court on September 18, according to thestack.technology.
What TeamPCP Actually Did
TeamPCP surfaced in late 2025 and built its reputation on supply-chain attacks that weaponized trust in open-source software. The group's core technique, according to Wired journalist Andy Greenberg as cited by Krebs, worked like a cycle: hackers would compromise a network where a widely used developer tool was being built, plant malware that spread to other developers' machines, then use stolen credentials to publish malicious versions of still more tools. Repeat, and the group's footprint kept growing.
The self-propagating worm at the center of it all, dubbed Shai-Hulud, first compromised more than 180 npm packages in September 2025, according to Help Net Security. A follow-up wave, "Mini Shai-Hulud," hit prominent libraries including TanStack, UiPath, and MistralAI in May, per CyberScoop.
CyberScoop, citing its own reporting, laid out a specific timeline: in late February, the group exploited a misconfigured workflow in Aqua Security's Trivy vulnerability scanner and stole a service-account token. Aqua rotated its credentials but missed some. On March 19, TeamPCP pushed a malicious Trivy release through every distribution channel simultaneously, embedding malware in thousands of automated build pipelines. Downstream victims included the European Commission and GitHub, CyberScoop reported. TechCrunch added that AI recruiting startup Mercor, LiteLLM, and OpenAI were also affected through the same chain of compromised packages.
Ars Technica reported the worm used an unconventional command-and-control mechanism, an Internet Computer Protocol-based "canister," a form of smart contract that let infected machines find control servers through URLs that could be changed rapidly, evading takedowns. Infected systems checked in roughly every 50 minutes.
Investigators told Help Net Security the campaign compromised more than 1,000 organizations worldwide, stole over 500,000 credentials, and exfiltrated at least 300 gigabytes of data, with global remediation costs estimated in the hundreds of millions of dollars.
A Recruiting Contest, and Sloppy Tradecraft
Krebs reported that in May, after the source code for the third version of Shai-Hulud leaked online, TeamPCP ran a contest offering $1,000 in Monero to whoever could run the largest supply-chain operation using it, with scoring based on how many downloads the compromised packages had. Threat intelligence firm Dataminr, quoted by Krebs, described the prize as a "recruitment floor," with the group allegedly telling participants better payouts were available for good access.
For a group this disruptive, the operational security was notably weak. Krebs, citing Aikido Security researcher Charlie Eriksen, reported that top-tier hacking groups typically invest heavily in infrastructure and tradecraft discipline to avoid exposure. TeamPCP did not, and it appears to have cost them.
Open Questions
The AFP's Commander Graeme Marshall said investigators are still working through a large volume of seized data and have not ruled out further arrests, according to Help Net Security. Prosecutors told thestack.technology they've already extracted 100 terabytes of data from seized devices and expect additional charges.
CyberScoop reported that Canadian threat intelligence firm Flare has traced Thomson's online activity, and that Oligo Security shared research suggesting the group's attacks date back as far as 2020. Help Net Security noted authorities say there is no indication TeamPCP was behind the earlier, separate S1ngularity and Shai-Hulud-linked incidents from that period. It remains unclear whether the U.S. Justice Department will seek extradition of either man, according to TechCrunch, which said the FBI did not comment when asked.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.