Australian authorities have arrested alleged masterminds behind TeamPCP, a group responsible for developing the Shai-Hulud worm and conducting supply chain attacks. The operation was conducted in collaboration with the FBI, marking a significant enforcement action against the threat actor group.
Australian police have charged two men in connection with TeamPCP, a cybercrime operation that embedded malware in open-source code to steal over 500,000 credentials from more than 1,000 organizations globally. The alleged scheme exploited the trust developers place in open-source software to distribute credential-stealing malware at scale across multiple sectors.
Oligo Security has connected the TeamPCP threat actor to ShadowRay 2.0 and traced its operations back to cryptojacking infrastructure active since 2020, suggesting a longer operational history than previously documented. The discovery links what may have appeared as separate threats into a cohesive campaign spanning multiple years and attack methodologies.