Cybersecurity News
Filters
Filtered by tag: open source security × Clear
Two Australians Charged Over TeamPCP Supply-Chain Attacks That Hit 1,000+ Organizations
Matched: Australia, cryptocurrency
Two Western Australian men have been charged with 14 offenses over alleged supply-chain attacks attributed to TeamPCP. Investigators say the pair planted malicious code in open-source repositories, compromising over 1,000 organizations globally, stealing 500,000+ credentials and exfiltrating 300GB of data. Remediation costs are estimated in the hundreds of millions. Warrants were executed in Cottesloe, Hamilton Hill, and Mandurah on 26 August 2026, with FBI involvement. Both men appeared in Perth Magistrates Court on 27 August 2026.
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
Matched: Australia
Two Western Australian men have been charged with 14 offences over their alleged roles in TeamPCP, a cybercrime group accused of compromising open-source security tools Trivy, Checkmarx KICS, and AI gateway LiteLLM in March 2026. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27.
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Matched: Australia
Two Australian men, aged 21 and 23, have been arrested by the Australian Federal Police over alleged ties to TeamPCP, a cybercrime group responsible for a prolonged series of software supply chain attacks. The group embedded malicious code in open source tools, using a self-propagating worm called Shai-Hulud to steal developer credentials and spread further. Investigators identified the 21-year-old as Ruben Thomson of Perth, whose online activity and poor operational security linked him to multiple cybercrime aliases. The pair face 14 combined charges and appeared in Perth Magistrates Court.
GitHub Expands Supply Chain Malware Detection From npm to 8 Package Registries
Matched: cryptocurrency
GitHub has expanded Dependabot's malware detection beyond npm to cover eight package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. The feature alerts developers to malicious dependencies capable of stealing passwords, API keys, cloud credentials, cryptocurrency wallets, and source code, offering broader protection against open-source supply chain attacks.
