Affected Systems

Global software supply chain: hundreds of open-source packages on GitHub, NPM, and other public repositories. Victims include 2,500+ organizations using compromised tools like LiteLLM (AI gateway), with major tech companies affected. No specific CVEs assigned; attacks involved credential theft and malicious code injection into developer tools.

Exploitation Status

Active exploitation confirmed. TeamPCP conducted supply chain attacks from late 2023 through 2025, using the Shai-Hulud worm to compromise developer credentials and inject malicious code. The group publicly released worm source code and ran a recruitment contest in May 2025. Arrests occurred but broader threat actor network remains active.

Business Impact

Organizations using open-source development tools face ongoing risk of compromised dependencies containing credential-stealing malware. Over 2,500 organizations had cloud service keys and secrets harvested via the LiteLLM compromise alone. The cyclical nature of the attack—compromising developer tools to reach more developers—creates cascading exposure. While two suspects are arrested, the decentralized "Cybercats" network of collaborating threat actors continues operations. Development teams may unknowingly be running compromised packages or have had credentials stolen months ago.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Audit all open-source dependencies in development and production environments, prioritizing packages from GitHub and NPM repositories accessed between late 2023 and present
  • Rotate all cloud service credentials, API keys, and secrets that were accessible from developer workstations or CI/CD pipelines during the exposure window
  • Review authentication logs for GitHub, NPM, and other code repository accounts for unauthorized access or unexpected package publishes
  • Implement software composition analysis (SCA) tools to detect known malicious packages and monitor for suspicious behavior in dependencies
  • Enforce multi-factor authentication on all developer accounts and code repository access, and review permissions for automated publishing tokens

---

# Threat Actor Context

Actor Profile

TeamPCP is a prolific cybercrime and data extortion collective responsible for the longest running software supply chain attack campaign on record. Rather than a structured criminal crew with a single operator, TeamPCP functions as a peer community of individually-skilled actors from multiple cybercriminal gangs who collaborate toward similar goals. The group emerged in late 2025 and operates through a Matrix chat server called "Cybercats" administered by George Prepakis (@kernelstub), who serves as the center of gravity for the collective. TeamPCP's primary motivation is financial gain through data extortion and credential theft. The group has demonstrated sophisticated recruitment tactics, including launching a $1,000 Monero contest to identify talent and acquire malicious access at scale. Two suspected members, aged 21 and 23 from Western Australia, were arrested by the Australian Federal Police in connection with creating malicious open-source software to extort thousands of global businesses.

TTPs (Tactics, Techniques, Procedures)

TeamPCP employs a cyclical exploitation methodology targeting software developers and supply chain infrastructure. Core TTPs include: credential phishing and theft targeting developers with access to public code repositories (GitHub, NPM); embedding malicious code in hundreds of open-source software tools; deploying the self-propagating worm "Shai-Hulud" to compromise corporate cloud environments and inject malware into open source development tools; stealing cloud service keys, API credentials, and secrets from compromised environments; and publishing malicious versions of legitimate software development tools to perpetuate the attack cycle. The group has also compromised code extensions and AI infrastructure components like LiteLLM. Their operations align with MITRE ATT&CK techniques including T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain), T1078 (Valid Accounts), T1552.001 (Unsecured Credentials: Credentials In Files), and T1059 (Command and Scripting Interpreter) for worm propagation.

Targets & Patterns

TeamPCP primarily targets the software development and technology sectors, with a specific focus on developers and organizations maintaining open-source software tools and AI infrastructure. The group's March 2025 attack on LiteLLM, an open-source AI gateway, harvested credentials from over 2,500 organizations including many of the world's top technology companies. In May 2025, TeamPCP compromised at least 3,800 code repositories at Microsoft-owned GitHub after a GitHub developer installed a compromised code extension. The targeting pattern demonstrates a preference for high-value supply chain nodes where a single compromise can cascade to thousands of downstream victims. By targeting popular code libraries and tools commonly used by developers, TeamPCP maximizes the reach and impact of each intrusion. Associated actors like Boxturtle have also targeted automobile manufacturers including BMW Group, Audi, Honda, Mercedes-Benz, Volvo, and Toyota. The group's contest scoring system, which rewarded participants based on weekly and monthly downloads of compromised packages, directly incentivized targeting the most widely-used code libraries.

Historical Context

TeamPCP emerged onto the cybercrime scene in late 2025 and has been conducting what security experts describe as the longest running software supply chain attack spree ever documented. The group gained significant attention in March 2025 with their attack on LiteLLM AI infrastructure, which affected over 2,500 organizations. In May 2025, they compromised at least 3,800 GitHub repositories and published the source code for the third iteration of their Shai-Hulud worm, subsequently launching a recruitment contest. The Cybercats Matrix chat server, created by George Prepakis (@kernelstub), has served as the coordination hub for TeamPCP and several other cybercrime entities over the past nine months. Members of this collective have been linked to multiple distinct cybercrime operations, including data breach brokering activities by associate Boxturtle (@xpl0itrsturtle) on Breachforums and Darkforums, and operations by FulcrumSec (SeesawSec). The arrests of two Western Australian suspects aged 21 and 23 represent the first known law enforcement action against TeamPCP members.

Defensive Recommendations

  • Implement strict code signing and verification processes for all open-source dependencies, with automated scanning for unexpected changes in package repositories
  • Deploy behavioral monitoring for T1195.002 (Supply Chain Compromise) by establishing baselines for legitimate developer tool behavior and alerting on anomalous code repository access patterns
  • Enforce multi-factor authentication with hardware tokens for all developer accounts accessing code repositories (GitHub, NPM, PyPI) and implement conditional access policies restricting access from unusual geolocations
  • Monitor for T1552.001 (Credentials In Files) by scanning cloud environments and code repositories for exposed API keys, cloud service credentials, and secrets using tools like TruffleHog or GitGuardian
  • Establish software bill of materials (SBOM) tracking for all dependencies and implement automated alerts when dependencies are updated, particularly for widely-used development tools and AI infrastructure components like LiteLLM

---

# Geopolitical Context

Geopolitical Context

The arrests by Australian Federal Police represent a significant law enforcement action against a decentralized, transnational cybercrime ecosystem that has exploited open-source software infrastructure to conduct what authorities describe as the longest-running software supply chain attack campaign on record. TeamPCP's operations—characterized by cyclical exploitation of developer credentials and self-propagating malware—targeted critical technology supply chains globally, including AI infrastructure (LiteLLM compromise affecting 2,500+ organizations) and major code repositories at Microsoft-owned GitHub. The group's structure appears consistent with emerging patterns in transnational cybercrime: a loosely affiliated network of skilled actors from multiple jurisdictions collaborating through encrypted communications platforms (Matrix chat server "Cybercats"), rather than a hierarchical organization. The case underscores the strategic vulnerability of open-source software ecosystems, which underpin critical infrastructure and commercial technology stacks worldwide, and highlights Australia's growing role in international cybercrime enforcement. The group's public recruitment efforts—including a $1,000 contest incentivizing supply chain attacks based on package download metrics—demonstrate sophisticated talent acquisition strategies that blur lines between cybercrime operations and competitive hacking communities.

State Actor Alignment

No state actor attribution is indicated in available reporting. TeamPCP appears to operate as a financially motivated cybercrime network without evident state sponsorship. The group's decentralized structure, use of cryptocurrency (Monero) for payments, and profit-driven extortion model are consistent with organized cybercrime rather than state-directed operations. Australian law enforcement cooperation with international partners (implied by the investigation's scope across multiple jurisdictions) suggests this is being treated as a transnational organized crime matter rather than a nation-state threat. The arrests occurred within Five Eyes partner Australia, and victims span Western technology firms and global enterprises, but no sanctions designations or state-nexus allegations have been publicly disclosed. The case may inform future policy discussions on securing open-source software supply chains, an area of increasing concern for Western governments following high-profile incidents like SolarWinds and the Log4j vulnerability.

Business Impacty pro region

The TeamPCP case carries significant implications for technology sectors across advanced economies. European organizations are likely among the 2,500+ entities compromised in the LiteLLM attack, given the widespread adoption of AI infrastructure and open-source tooling across EU member states. The compromise of major automotive manufacturers (BMW Group, Audi, Mercedes-Benz, Volvo) by associated actors suggests particular exposure in Europe's industrial base. For the Indo-Pacific region, Australia's successful arrests may strengthen its position as a cybersecurity partner within the Quad and Five Eyes frameworks, demonstrating capability to investigate and disrupt sophisticated transnational cyber threats. The case highlights systemic risk in global software supply chains: open-source repositories like GitHub and NPM serve as critical infrastructure for software development worldwide, and their compromise enables cascading effects across sectors and borders. North American technology firms—including victims of the GitHub breach affecting 3,800+ repositories—face continued exposure to supply chain attacks that exploit trusted developer tools. The arrests may prompt increased scrutiny of open-source security practices and developer credential management across OECD economies, potentially influencing regulatory approaches to software supply chain security in the EU (under NIS2/CER directives) and the United States (following Executive Order 14028 on cybersecurity).

Forecast

If Australian prosecutors successfully build cases against the two suspects, the proceedings may yield additional intelligence on TeamPCP's operational structure and international collaborators, potentially enabling further law enforcement actions in other jurisdictions. However, given the decentralized nature of the "Cybercats" network and the group's recruitment model, disruption of the two Western Australian suspects is unlikely to eliminate the broader threat; other participants in the supply chain attack contest and affiliated actors may continue operations under different branding. If the investigation reveals additional identities of core members—particularly the individual operating as "kernelstub" (George Prepakis) if not among those arrested—coordinated international arrests could follow within months. The case may accelerate policy responses: if legislators in the US, EU, or other jurisdictions perceive open-source supply chain attacks as an escalating threat, regulatory requirements for software bill of materials (SBOM), code signing, and repository security controls could advance within 12-18 months. If TeamPCP's tactics are adopted by more sophisticated threat actors—including state-sponsored groups—the cyclical exploitation model could become a persistent feature of the threat landscape, necessitating sustained investment in developer security awareness and multi-factor authentication enforcement across code repositories. The public nature of the arrests may temporarily deter some participants in cybercrime recruitment contests, though financial incentives and perceived anonymity are likely to sustain interest among aspiring actors in the near term.