Executive Summary
In August 2026, Australian Federal Police arrested two men aged 21 and 23 from Western Australia in connection with TeamPCP, a prolific cybercrime syndicate responsible for the longest-running software supply chain attack campaign ever recorded. The group executed sophisticated attacks starting in late 2025, embedding malicious code in hundreds of open-source software tools through their self-propagating Shai-Hulud worm, compromising developer credentials at repositories like GitHub and NPM, and extorting victims for profit. Their attacks impacted over 2,500 organizations including major technology companies, with notable breaches of LiteLLM AI infrastructure and over 3,800 GitHub repositories.
This incident highlights the growing threat of AI-enabled cybercrime and supply chain vulnerabilities as threat actors increasingly leverage large language models to compress the knowledge gap between attack research and operational execution, enabling less experienced criminals to operate at unprecedented scale without traditional operational discipline.
Why This Matters Now
Supply chain attacks are surging as threat actors exploit the interconnected nature of modern software development, with AI tools lowering barriers for less sophisticated criminals to execute complex campaigns at scale, making robust software supply chain security controls critical for organizations.
Attack Path Analysis
TeamPCP conducted a sophisticated supply chain attack by compromising developer credentials and injecting malicious code into popular open source repositories, enabling lateral movement across victim networks through the self-propagating Shai-Hulud worm. The attackers established command and control through Matrix chat servers and Telegram, exfiltrated cloud service keys and sensitive data from over 2,500 organizations including major technology companies, and caused significant business disruption by forcing platform-wide security changes at GitHub and other code repositories.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
TeamPCP gained initial access by phishing developer credentials at public code repositories like GitHub and NPM, then injected malicious code into popular open source software tools and libraries including LiteLLM AI gateway
MITRE ATT&CK® Techniques
Compromise Software Supply Chain
Valid Accounts: Cloud Accounts
Credentials from Password Stores: Cloud Secrets Management Stores
Compromise Infrastructure: Botnet
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Data Encrypted for Impact
Obtain Capabilities: Exploits
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Supply Chain Risk Assessment
Control ID: ID.RM-3
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.12
Digital Operational Resilience Act (DORA) – ICT Third-Party Risk Management
Control ID: Article 28
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2
PCI DSS 4.0 – Software Development Lifecycle Security
Control ID: 6.2.4
ISO 27001:2022 – Information Security Policy for Supplier Relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Supply chain attacks targeting open-source repositories directly compromise software development workflows, requiring enhanced code validation and zero-trust segmentation controls.
Information Technology/IT
Malicious code injection in development tools creates lateral movement risks across IT infrastructure, demanding stronger east-west traffic security and egress filtering.
Computer/Network Security
TeamPCP's exploitation of GitHub credentials and AI infrastructure exposes cybersecurity vendors to reputational damage and requires multicloud visibility capabilities.
Health Care / Life Sciences
Supply chain compromises affecting cloud environments threaten HIPAA compliance requirements, necessitating encrypted traffic controls and threat detection systems.
Sources
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australiahttps://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/Verified
- Australian Federal Police Statement on TeamPCP Arrestshttps://www.afp.gov.au/news-media/media-releasesVerified
- TeamPCP Supply Chain Attacks Analysishttps://www.wired.com/story/teampcp-supply-chain-attacks/Verified
- CloudSEK Analysis of LiteLLM Compromisehttps://cloudsek.com/threatintelligence/teampcp-litellm-supply-chain-attackVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain TeamPCP's supply chain attack by limiting lateral propagation between development environments and reducing the blast radius of compromised credentials across cloud infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware access controls would likely limit the scope of compromised developer accounts, constraining their ability to access cloud infrastructure beyond authorized development environments and reducing credential reuse across multiple platforms.
Control: Zero Trust Segmentation
Mitigation: Workload isolation policies would likely constrain privilege escalation by limiting compromised accounts to their designated cloud segments, reducing the ability to access production environments or administrative cloud service accounts across organizational boundaries.
Control: East-West Traffic Security
Mitigation: Traffic inspection and micro-segmentation would likely constrain worm propagation between cloud workloads, limiting the ability to spread laterally across development environments and reducing the reach of self-propagating malicious code in cloud infrastructure.
Control: Multicloud Visibility & Control
Mitigation: Unified visibility across cloud environments would likely detect suspicious communication patterns from compromised workloads, constraining persistent C2 channels and reducing the attackers' ability to coordinate operations across multiple cloud platforms undetected.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely constrain large-scale data exfiltration by monitoring and restricting outbound data flows from cloud workloads, reducing the volume and scope of sensitive information that could be transferred to external breach forums.
Despite security controls constraining the attack scope, residual impact would likely include reduced trust in development toolchains and potential exposure of cloud assets that were accessed before segmentation policies could be fully enforced across all environments.
Impact at a Glance
Affected Business Functions
- Software Development
- AI Infrastructure
- Cloud Services
- Open Source Package Management
Estimated downtime: 7 days
Estimated loss: N/A
Cloud service keys, API credentials, authentication tokens, and proprietary source code from over 2,500 organizations including major technology companies. Compromised GitHub repositories containing intellectual property and development secrets from 3,800+ code repositories.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between development environments and production systems, limiting blast radius of supply chain compromises
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration to external repositories and breach forums
- • Enable Multicloud Visibility & Control to monitor anomalous interactions across development platforms and detect suspicious automation patterns
- • Establish Threat Detection & Anomaly Response capabilities to identify compromised developer accounts and malicious code injection attempts
- • Implement East-West Traffic Security controls to prevent worm propagation between workloads and contain supply chain attacks within isolated network segments



