TeamPCP Arrests Leave the Secret Theft Intact

Australian Federal Police and Western Australia Police arrested and charged two Perth men on August 27, saying they were principal participants in TeamPCP’s supply-chain campaign that hit more than 1,000 organizations and led to at least 500,000 stolen credentials and 300GB of exfiltrated data. The FBI said the malicious code may have affected organizations worldwide through compromised developer tooling and package releases. The campaign worked by planting malicious code in trusted open-source tools and packages, so developers installed it through normal build and update paths. Once inside, it stole publishing credentials and other secrets, which let the attackers keep pushing poisoned releases from the inside and move from one compromise to the next. The arrests help attribution, but they do not erase the exposure already baked into CI/CD, publishing, and cloud credentials taken during the campaign. If those secrets were usable beyond the original compromise window, the long tail belongs to whoever can still reach the affected developer workflows, not just to the people now in custody.

Part of the PlainSec briefing for 2026-08-27

Every edition of this story: TeamPCP Arrests Leave the Secret Theft Intact

Sources