Australia charges two alleged members of hacking group TeamPCP
Australian Federal Police arrested two men over alleged involvement in TeamPCP, the group behind supply-chain attacks that compromised more than 1,000 organizations.
The Australian Federal Police said two men have been arrested and charged with 14 offenses over alleged participation in cybercrimes for TeamPCP, a hacking group that authorities say compromised more than 1,000 organizations worldwide over nine months.
Police did not name the men, saying only that they lived in the Western Australian towns of Cottesloe and Mandurah. KrebsOnSecurity, citing a lengthy investigation, published what it reports to be both defendants' names along with background on the mistakes that led to their arrests. Authorities say that if convicted, one man faces more than 20 years in prison and the other more than 10.
How the Shai-Hulud worm spread
TeamPCP emerged in December and is best known for a sustained run of supply-chain attacks that laced open source software with self-propagating malware. The worm, dubbed Shai-Hulud, targeted organizations' CI/CD pipelines. Once a package or tool was compromised, the worm attached itself to future updates, so developers who downloaded and ran those packages through their own pipelines also became infected.
A separate component harvested credentials for other packages from the memory of infected hardware, which TeamPCP then used to infect those packages. In one case the group compromised the Trivy vulnerability scanner, and the infection spread downstream to KICS, the Telnyx Python SDK and LiteLLM. The initial Trivy compromise led to the theft of terabytes of credentials and other private data.
To keep its credential-collection channel resistant to takedowns, Shai-Hulud used a smart contract form known as an Internet Computer Protocol-based canister, letting it locate control servers through URLs that could be changed at any time. Infected machines reported to the canister every 50 minutes.
Brian Krebs wrote that TeamPCP members lacked the operational discipline usually seen in groups at that level. Citing Aikido Security researcher Charlie Eriksen, Krebs reported that attackers of this caliber traditionally spent significant time on research, code tuning and infrastructure. "LLMs have compressed that gap significantly," Eriksen said.
More at Ars Technica.