Executive Summary
In August 2026, Australian Federal Police arrested two men aged 21 and 23 in connection with the TeamPCP hacking group's extensive supply chain attacks targeting developer platforms and open-source repositories. The group compromised trusted software components including packages from Trivy, LiteLLM, SAP, and TanStack, while also breaching high-profile organizations like OpenAI, GitHub, and the European Commission. Their malicious code injection campaigns affected over 1,000 organizations globally, resulting in the theft of 500,000 credentials and exfiltration of 300GB of data, with estimated remediation costs reaching hundreds of millions of dollars.
This incident highlights the growing threat of supply chain attacks as cybercriminals increasingly target the software development ecosystem to achieve massive scale impact. With organizations' heavy reliance on open-source components and third-party packages, these attacks demonstrate how compromising a few trusted software elements can cascade into global security incidents affecting critical infrastructure and enterprise systems.
Why This Matters Now
Supply chain attacks targeting developer ecosystems have become the preferred method for achieving widespread compromise with minimal effort. As organizations accelerate digital transformation and increase dependency on open-source components, the attack surface expands exponentially, making robust supply chain security controls more critical than ever.
Attack Path Analysis
TeamPCP conducted supply chain attacks by injecting malicious code into trusted open-source repositories and packages, compromising developer environments to steal credentials and source code. The attackers escalated privileges through compromised developer accounts, moved laterally across connected systems and organizations, maintained command and control through encrypted channels, exfiltrated over 300GB of data including 500,000 credentials, and caused hundreds of millions in global remediation costs across over 1,000 organizations.
Kill Chain Progression
Initial Compromise
Description
TeamPCP injected malicious code into trusted open-source software packages and repositories including Trivy, LiteLLM, Telnyx, SAP, and TanStack, which developers unknowingly incorporated into their applications
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Supply Chain
Valid Accounts
Command and Scripting Interpreter: PowerShell
Credentials from Password Stores: Credentials from Web Browsers
Exfiltration Over C2 Channel
Indicator Removal: File Deletion
Obfuscated Files or Information
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Development Security
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.12
DORA – ICT Third-Party Risk Management
Control ID: Article 11
CISA ZTMM 2.0 – Data Access Control
Control ID: DA-1
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – Information Security Policy for Supplier Relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical exposure to supply-chain attacks targeting open-source repositories, developer platforms, and software packages with potential compromise of development infrastructure and source code theft.
Information Technology/IT
High risk from TeamPCP-style attacks compromising IT infrastructure through malicious code injection, credential theft, and lateral movement across enterprise networks and cloud environments.
Financial Services
Significant vulnerability to supply-chain compromises affecting trading platforms, payment systems, and financial applications with regulatory compliance implications under PCI and banking standards.
Government Administration
Major security concerns following European Commission breach, highlighting risks to government systems from compromised software packages and potential exposure of sensitive administrative data.
Sources
- Australia arrests alleged TeamPCP hackers behind supply-chain attackshttps://www.bleepingcomputer.com/news/security/australia-arrests-alleged-teampcp-hackers-behind-supply-chain-attacks/Verified
- Australian Federal Police - Two WA men charged following AFP, FBI, WAPF disruption of alleged global cybercrime operationhttps://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-globalVerified
- TeamPCP Software Supply Chain Attacks - Flare Investigationhttps://flare.io/learn/resources/blog/teampcp-software-supply-chain-attacksVerified
- Two Alleged TeamPCP Hackers Arrested in Australia - Krebs on Securityhttps://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would likely constrain TeamPCP's multi-stage supply chain attack through workload segmentation and controlled network paths. The comprehensive segmentation approach could reduce lateral movement scope and limit exfiltration channels across the compromised development infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Malicious packages would likely still achieve initial compromise, but CNSF workload isolation could reduce the attack surface and limit compromised container reachability to other development infrastructure components.
Control: Zero Trust Segmentation
Mitigation: Compromised credentials would likely still provide initial access, but zero trust segmentation could limit the scope of privilege escalation by restricting access to identity-verified network segments and reducing unauthorized resource reachability.
Control: East-West Traffic Security
Mitigation: Lateral movement between organizations and environments would likely be significantly constrained through east-west traffic inspection and segmentation policies that reduce attacker reachability across connected development infrastructure.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications may still occur, but multicloud visibility could provide enhanced detection capabilities and network path control that limits attacker coordination channels across distributed cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration volume and scope would likely be reduced through egress policy enforcement that controls outbound data flows and limits unauthorized external communications from compromised development environments.
Overall impact scope would likely be reduced through constrained lateral movement and limited data exfiltration, potentially reducing the number of affected organizations and the volume of compromised credentials requiring remediation.
Impact at a Glance
Affected Business Functions
- Software Development and DevOps
- Source Code Management
- Credential Management Systems
- Open Source Package Distribution
Estimated downtime: 30 days
Estimated loss: $500,000,000
Compromised over 500,000 credentials including developer authentication tokens, API keys, and access secrets. Exfiltrated at least 300GB of data including source code repositories from major organizations like OpenAI, Mistral AI, SAP, and the European Commission. Affected over 1,000 organizations worldwide through supply chain contamination.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between developer environments and production systems using identity-based policies and microsegmentation
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts to external destinations
- • Enable Multicloud Visibility & Control to monitor anomalous interactions and suspicious automation across development infrastructure
- • Establish Threat Detection & Anomaly Response capabilities to baseline normal developer behavior and alert on covert tool usage
- • Implement East-West Traffic Security to monitor and control workload-to-workload communications within development environments



