Australian Police Charge Two Over TeamPCP Credential Theft
Australian police have charged two men in connection with TeamPCP, a cybercrime operation that embedded malware in open-source code to steal over 500,000 credentials from more than 1,000 organizations globally. The alleged scheme exploited the trust developers place in open-source software to distribute credential-stealing malware at scale across multiple sectors.
Oligo Security has connected the TeamPCP threat actor to ShadowRay 2.0 and traced its operations back to cryptojacking infrastructure active since 2020, suggesting a longer operational history than previously documented. The discovery links what may have appeared as separate threats into a cohesive campaign spanning multiple years and attack methodologies.
AI supply chain risks are predominantly emerging in developer workflows and open-source package repositories rather than in more sophisticated attack vectors like poisoned model weights or compromised MCP servers, according to Zentera Systems CEO Dr. Jaushin Lee. Lee advocates for network segmentation as a more cost-effective risk mitigation strategy than tooling alone and recommends that software teams adopt semiconductor isolation practices to strengthen their defenses. He also addresses the limitations of self-hosted models in protecting against these evolving supply chain threats.