Australian authorities arrested two alleged members of TeamPCP, a prolific hacking group responsible for supply-chain attacks that compromised over 1,000 organizations worldwide. The group used a self-propagating worm called Shai-Hulud to infect open-source software via CI/CD pipelines, spreading maliciously through package ecosystems.
Background
TeamPCP emerged in December as one of the most damaging supply-chain attack groups, using the Shai-Hulud worm to compromise CI/CD pipelines and open-source package ecosystems. This case represents a significant enforcement action against a group with widespread global impact.
- Source
- Ars Technica
- Published
- Aug 28, 2026 at 07:15 PM
- Score
- 8.0 / 10