Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialKey Takeaways
Australian law enforcement officials, working with the U.S. Federal Bureau of Investigation, arrested two men Wednesday on cybercrime charges. The men allegedly are members of a global cybercrime syndicate suspected of creating the Shai-Hulud worm, malicious software that victimized thousands of businesses around the world.
The Australian Federal Police said the syndicate, TeamPCP, is estimated to have enabled the theft of more than 500,000 credentials and at least 300GB of data. The financial impact of the gang’s activities includes global remediation costs in the hundreds of millions of dollars, the AFP said.
The group made headlines in late 2025 when it began compromising corporate cloud environments with the self-propagating worm. Shai-Hulud stole credentials from developers working on projects that use open source code repositories such as GitHub and npm.
It was originally documented in 2025 by ReversingLabs (RL) researchers, who noted that Shai-Hulud systematically harvested npm tokens, GitHub credentials, and cloud provider secrets from compromised developer environments using tools such as TruffleHog. The malware then leveraged those credentials to tamper with additional packages and repositories, effectively turning the software supply chain itself into a propagation mechanism.
AFP Commander Graeme Marshall said in a statement about the arrests:
“Cybercrime syndicates are becoming increasingly organized and often operate like professional businesses, but our investigators are relentless in tracking down criminals who attempt to exploit digital anonymity to attack our community.”
Here’s what the arrests of the two alleged threat actors involved in the cascading supply chain attack means.
[ Why RL Built Spectra Assure Community | Sign up for Free ]
TeamPCP has been one of the most active threat actors over the last year, said Danny Jenkins, CEO of Threatlocker, and arrests in connection with the group are an incredibly important step toward dismantling it.
“Like with most organized crime investigations, law enforcement will be looking to learn as much as they can from the individuals arrested. The arrests also speak well of the extensive cooperation the U.S. and Australia have had on cybersecurity through both law enforcement and the Five Eyes intelligence-sharing network.”
—Danny Jenkins
Lina Dabit, executive director and field CISO at Optiv Canada, said she is impressed to see collaboration beyond just law enforcement agencies to include private-sector organizations.
“Make no mistake, threat actor groups collaborate better than we do. Seeing investigations like this one highlights how critical it is for defenders to work better together.”
—Lina Dabit
However, Dabit said that arresting two principal participants won’t end TeamPCP because “oftentimes when you cut the head off the snake, it grows two more.”
Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs, said the arrests show the value of private-sector intelligence feeding into traditional law enforcement.
“The joint AFP-FBI investigation began in April after cybersecurity companies provided key information, and arrests followed months later.”
—Jacob Krell
Krell said one thing that distinguishes TeamPCP in the cybercrime sphere is scale.
TeamPCP is blamed for what KrebsOnSecurity describes as the longest-running spree of software supply chain attacks on record, Krell noted.
They are also efficient. “In just one five-day period in March, CloudSEK data analyzed by StepSecurity showed 78,330 secrets exfiltrated from the CI/CD pipelines of 2,186 organizations, including public companies with a combined market capitalization above $6 trillion,” he said.
Another distinguishing feature of the group is the way it franchised supply chain attacks by open-sourcing the technique.
“Ransomware-as-a-service groups generally control access to their operational tooling through an affiliate structure. TeamPCP did something different. It released Shai-Hulud as open-source attack tooling and then crowdsourced its deployment through a paid contest.”
—Jacob Krell
Collin Hogue-Spears, senior director of solution management at Black Duck Software, said TeamPCP targets an organization’s security tooling — the scanners that run inside build pipelines. “One poisoned release turned an auditor into a thief across the pipelines that pulled it,” he said.
“Most crews guard their tooling. This one published its worm framework on GitHub in May and, by Brian Krebs’ account, ran a $1,000 contest for whoever used it to compromise the most-downloaded packages.”
—Collin Hogue-Spears
Mini Shai-Hulud re-emerged in May, compromising more than 160 npm open-source software (OSS) packages, many of them popular and widely used, with millions of weekly downloads — which rocked trust in open-source repos.
At the time, the TanStack team disclosed that attackers published malicious versions of 42 @tanstack/* packages to npm after the threat actors successfully compromised publishing credentials. The breach includes packages like @tanstack/react-router which has more than 12 million weekly downloads.
Tomislav Peričin, RL’s co-founder and chief software architect, said TeamPCP was targeting strategic open-source assets.
“That’s not a niche library; it’s load-bearing infrastructure for huge swaths of the JavaScript ecosystem, consumed directly and transitively.”
—Tomislav Peričin
TeamPCP is also distinguished by its brazenness and audacity in how it operates. “This trend really started emerging a few years ago,” Dabit said. “We saw it with Scattered Spider, who ironically has some significant crossover with TeamPCP, and the profiles of the young people, often young men, whose sole purpose was to upstage their peers. The notoriety and bragging rights were often more important than the illicit gains.”
This need for oneupmanship has led to greater risks for victim organizations, including a move toward personal targeting of employees, Dabit said.
“TeamPCP points to a new breed of cybercriminal, ones who have no internal rules or constraints, as we saw in the past. This should concern all of us, because where does it stop? The line has been crossed.”
—Lina Dabit
Although the AFP did not release the names of the two alleged gang members that they arrested, they did release their ages: 21 and 23. Despite their youth, Dabit noted, they apparently were already successfully carrying out impactful exploits, and he wondered where might they be in five or 10 years.
Krell doubted that the arrests would have a long-term impact on TeamPCP. The alleged leader told KrebsOnSecurity that he stopped operating with TeamPCP in March and that another individual had taken over. "Ñ”More importantly, the August 4 Shai-Hulud wave hit more than 400 npm packages just three weeks before these arrests,” he said.
Krell also noted that TeamPCP had already open-sourced the worm and turned its use into a criminal contest. “Arresting the alleged operators doesn’t recall the source code. Once offensive tooling has been published and copied, the capability no longer depends on the people who created it,” Krell said.
“That’s the uncomfortable legacy of this campaign. Law enforcement can arrest alleged operators, but it can’t make a published technique unpublished.”
—Jacob Krell
Hogue-Spears advised that the strategic takeaway for security leaders is that they must pin every third-party GitHub Action and container image to an immutable commit SHA or digest, not a version tag. They must also rotate every long-lived personal access token and registry publish token a CI runner has held at any point since February, he added.
“If your pipeline still pulls a dependency by tag and keeps a long-lived token in the runner, the next poisoned tag harvests that token. No arrest changes that.”
—Collin Hogue-Spears
Shai-Hulud is here to stay. RL’s Peričin has stressed that Shai-Hulud underscored the importance of transparency and integrity across open-source ecosystems, dependencies, and CI/CD pipelines. To respond, developers and development organizations must back efforts to strengthen both, which GitHub agrees with.
Peričin stressed that the industry needs to enable comprehensive software supply chain security. “Until that happens, another self-replicating malware could worm its way into trusted development infrastructure,” he said.
“After all, if you don’t know which packages you’re building software with — the content of your build pipeline — then someone else will figure it out and use that knowledge against you. Embracing package reputation; SBOMs; deferred package updates; and artifact provenance are no longer nice-to-haves. They’re essential to modern cyber defense as attackers look to compromise sensitive organizations by injecting malicious code upstream in their software supply chain.”
—Tomislav Peričin
The software supply chain is complex and requires augmentation of traditional application security (AppSec) checks with more nuanced, behavioral-based detection that can spot malicious code and other anomalies, he said.
“These software supply chain security measures won’t end attacks for good, but they will raise the bar and block many noisy, disruptive campaigns — for the benefit of everyone.”
—Tomislav Peričin



UAT-10147 leveraged agentic AI to go beyond scripting to deliver a backdoor. The method highlights the need for agentic SOCs.

The annual cybersecurity conference focused on frontier AI agents — and what they mean for cyber. Here are three key takeaways.

Researchers built a worm that reasons about hosts it infects, and the open-weight models powering it sit outside AI-provider safety controls.