INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Australian Police Charge Two Over TeamPCP Credential Theft

| 2026-08-27 14:09 CRITICAL MEDIUM
Executive Summary
AI-generated
The Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. The FBI confirmed the involvement of the US agency, with charges brought against the suspects following joint investigations between the AFP and Western Australia Police Force into a sophisticated cybercrime syndicate working in parallel with the Federal Bureau of Investigation.
Technical Mitigations AI-generated
* Implement secure coding practices and use static analysis tools to detect potential vulnerabilities in open-source code. * Use version control systems like Git with proper access controls and monitoring for suspicious activity. * Regularly update and patch dependencies, libraries, and frameworks used in enterprise CI/CD pipelines and cloud infrastructure workflows. * Conduct regular security audits and penetration testing on software applications and supply chains to identify potential entry points for malicious actors.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
TeamPCPTeamPCP SANDCLOCKSANDCLOCKMini Shai-HuludMini Shai-HuludCanisterWormCanisterWorm
Target & Sectors
FIVE_EYES FIVE_EYES technologytechnology
Incident Timeline
‎March 2026
The Australian Federal Police charged two Western Australian men with TeamPCP credential theft.
attribution The Australian Federal Police
general_metric 14 offences
threat_actor TeamPCP
‎April, 2026
The Australian Federal Police (AFP) and the FBI launched investigations into two individuals who allegedly stole credentials for TeamPCP users.
attribution AFP
attribution FBI
‎May 12, 2026
The group used the Mini Shai-Hulud worm framework to open-source its code on GitHub.
malware Mini Shai-Hulud
organisation GitHub
‎July 2
The Federal Bureau of Investigation (FBI) issued a July 2 advisory to affected organizations.
attribution the Federal Bureau of Investigation (FBI
‎August 4, 2026
Threat actors used npm to compromise keyv and cacheable packages.
‎August 5
TeamPCP linked infrastructure was traced back to 2020 and tied to activity previously tracked as TA-NATALSTATUS through overlapping domains, malware deployment paths, staging techniques, and backend infrastructure.
threat_actor TeamPCP
organisation Oligo Security
organisation TA-NATALSTATUS
organisation IronErn
‎26 August 2026
The Australian Federal Police executed search warrants in Perth on 26 August 2026.
target_region Australia
attribution The Australian Federal Police
attribution the Western Australia Police Force
attribution FBI
‎2026/08/26
The Australian Federal Police (AFP) executed search warrants in Perth with assistance from the FBI.
attribution AFP
attribution FBI
general_metric 14 offences
‎26 August, 2026
The Australian Federal Police (AFP) executed search warrants in Perth with assistance from the FBI.
attribution AFP
attribution FBI
general_metric 14 offences
‎August 27, 2026
Threat actors used stolen credentials to gain unauthorized access to electronic devices in Perth, Australia.
target_region Australia
attribution AFP
attribution the Western Australia Police Force
attribution Perth Magistrates Court
general_metric 23 Louis Michael Gaebler
‎August 27
The Australian Police charged two individuals for TeamPCP credential theft.
organisation Hacker News
general_metric 200 HTTP
‎2026/08/27
Two men from Western Australia were charged with various cybercrime offenses related to the TeamPCP credential theft operation.
data_breach 500,000 credentials
threat_actor TeamPCP
victims 1,000 organizations
organisation Hackers Charged
organisation Major Supply Chain Attacks
data_breach 300 gigabytes
organisation AFP
victims 16 organizations
organisation PyPI
organisation GitHub Actions
organisation CI
infrastructure Windows
financial 100,000 order
organisation CloudSEK
victims 2,500 organizations
infrastructure 434,000 CD pipelines
infrastructure 2,488 corporate domains
data_breach 153 GB
organisation StepSecurity
organisation GitLab
organisation DevOps
organisation Bitbucket Pipelines
victims 1,064 organizations
organisation Oligo
organisation Socket
‎August 2026
The Australian Federal Police and the Western Australia Police Force worked with the FBI to charge two individuals, who were principal participants in TeamPCP, a syndicate that inserted malicious code into software hosted on public repositories.
data_breach 500,000 credentials
data_breach 300 gigabytes
threat_actor TeamPCP
organisation PyPI
organisation OpenAI
organisation KICS
organisation the Telnyx
organisation CI
organisation API
organisation AWS
organisation GCP
organisation Kubernetes ServiceAccount
financial 100,000 order
Tactical Metrics
Metrics
data_breach
500,000
Credentials
Metrics
data_breach
300
Gigabytes
Metrics
victims
1,000
Organizations
Metrics
financial
100,000
Order
Metrics
infrastructure
‎Windows
Affected Product
Metrics
victims
2,500
Organizations
Metrics
infrastructure
434,000
Cd Pipelines
Metrics
infrastructure
2,488
Corporate Domains
Metrics
data_breach
153
Gb
Metrics
victims
16
Organizations
Metrics
victims
1,064
Organizations
Intelligence Sources