Big Launches

Australian duo named principal members of TeamPCP

 ·  By Flavia Pembridge
Australian duo named principal members of TeamPCP - teampcp hackers
Australian duo named principal members of TeamPCP

Australian authorities have charged two Western Australian men as alleged principal participants of the TeamPCP hacking group after coordinated raids in Cottesloe, Hamilton Hill and Mandurah.

Arrests and charges

The operation, involving the Australian Federal Police, WA Police and the FBI, resulted in the detention of a 21‑year‑old from Cottesloe and a 23‑year‑old from Mandurah. The individuals have been identified as Ruben Thomson and Louis Gaebler.

Federal officials said the two are accused of inserting malicious code into open‑source software that was later downloaded by other developers. “These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organisations worldwide,” said FBI cyber division assistant director Brett E Leatherman.

Leatherman added, “We are proud to work with the Australian Federal Police and the Western Australia Police Force to … combat the growing threat of software supply chain attacks.”

Scope of the supply‑chain intrusion

Police allege the compromised code was distributed through several popular open‑source tools, including a vulnerability scanner, AI API proxy library LiteLLM, Checkmarx’s GitHub Actions workflows and OpenVSX plugins. The infected versions were then deployed across government, academia and private‑sector networks.

Authorities estimate the campaign could have affected over 1,000 entities worldwide. They further claim the breach enabled the theft of more than 500,000 credentials and the exfiltration of at least 300 gigabytes of data.

Remediation costs run into hundreds of millions.

According to the joint statement, the expenses are projected to reach the hundreds of millions of dollars.

TeamPCP is known to have compromised an open-source vulnerability scanner, publishing malicious versions that organisations unwittingly downloaded. The group’s campaigns also hit the artificial intelligence application programming interface proxy library LiteLLM, and Checkmarx’s GitHub Actions workflows and OpenVSX plugins.

As iTnews reported earlier this month, the National Disability Insurance Agency (NDIA) was among the domestic victims of TeamPCP, although the agency suggested little damage was incurred courtesy of its defence-in-depth approach and layered tooling.

The Australian Federal Police said that industry and international cooperation was critical in positioning authorities to take action. “The most effective law enforcement outcomes are achieved when agencies share intelligence, expertise, and resources across borders,” commander Graeme Marshall said. “In this matter, the information provided to authorities by a number of threat assessment companies proved key for investigators. “Early reporting and sustained cooperation between organisations and law enforcement play a critical role in supporting cybercrime investigations, protecting affected individuals, and mitigating the broader impact of cybercrime across the Australian community.”

The case highlights the growing challenge of software supply‑chain security and the need for continuous vigilance among developers and users alike.

Leave a Comment

Your email address will not be published.