← Back
Supply ChainGraham Cluley·3 hours ago

Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more

Two individuals have been charged in connection with TeamPCP's extensive global supply chain attack campaign that compromised over 1,000 organizations and resulted in the theft of approximately 500,000 credentials, with OpenAI among the affected victims. The attackers deployed a self-propagating worm dubbed Shai-Hulud in their operation, demonstrating the sophisticated nature of their coordinated hacking spree. This case highlights the significant reach and impact of organized cyber threats targeting critical infrastructure and technology companies worldwide.

Read full article at Graham Cluley

Related Articles

Supply ChainThe Register·10 hours ago

Australian cops cuff alleged TeamPCP masterminds

Australian authorities have arrested alleged masterminds behind TeamPCP, a group responsible for developing the Shai-Hulud worm and conducting supply chain attacks. The operation was conducted in collaboration with the FBI, marking a significant enforcement action against the threat actor group.

Supply ChainSecurity Affairs·1 day ago

Australian Police Charge Two Over TeamPCP Credential Theft

Australian police have charged two men in connection with TeamPCP, a cybercrime operation that embedded malware in open-source code to steal over 500,000 credentials from more than 1,000 organizations globally. The alleged scheme exploited the trust developers place in open-source software to distribute credential-stealing malware at scale across multiple sectors.

MalwareInfosecurity Magazine·3 weeks ago

TeamPCP Traced Back to 2020 Cryptojacking Operation

Oligo Security has connected the TeamPCP threat actor to ShadowRay 2.0 and traced its operations back to cryptojacking infrastructure active since 2020, suggesting a longer operational history than previously documented. The discovery links what may have appeared as separate threats into a cohesive campaign spanning multiple years and attack methodologies.