Australian Federal Police arrested two men from Western Australia in connection with TeamPCP, a cybercrime group responsible for an extended campaign of software supply chain attacks. The suspects, aged 21 and 23, remain unnamed in official statements but were taken into custody for alleged involvement in creating malicious open-source software used to target thousands of businesses globally.
According to the AFP statement, the pair operated within a "sophisticated cybercrime syndicate" that distributed compromised code through supply chain channels. TeamPCP has earned notoriety for running what security researchers describe as the longest continuous spree of software supply chain attacks on record.
The investigation connects to earlier reporting by KrebsOnSecurity, which identified the 21-year-old suspect in June and subsequently maintained communication with individuals linked to the group. KrebsOnSecurity's reporting included interviews with someone claiming to serve as TeamPCP's spokesperson and analysis of digital evidence left by the group members.
The arrests represent a significant law enforcement action against supply chain compromise operations, a threat vector that has gained prominence in recent years. Software supply chain attacks allow threat actors to compromise numerous downstream users by poisoning shared code repositories or development tools, multiplying the potential impact of individual compromise operations.
The AFP investigation outcome demonstrates growing international focus on disrupting cybercriminal networks operating through software distribution channels. Supply chain compromises present distinct investigative challenges because attacks often remain undetected for extended periods, and attribution requires tracking malicious code across multiple platforms and repositories.
The case underscores how open-source software ecosystems, which depend on community contributions and trust, face exploitation from actors seeking broad access to enterprise networks. TeamPCP's operational approach leveraged this inherent vulnerability in distributed development workflows.
The investigation appears ongoing, with authorities continuing to examine the scope of the group's activities and identifying additional victims. The AFP did not disclose details regarding specific malware families deployed
