<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Australia arrests alleged TeamPCP hackers behind supply-chain attacks]]></title><description><![CDATA[<p dir="auto">Australian authorities have arrested and charged two young men for their alleged involvement with the <strong>TeamPCP</strong> hacking group, which is believed to be behind a series of widespread developer supply-chain attacks. The arrests mark a significant step in an investigation that has spanned multiple countries and affected thousands of downstream victims.</p>
<p dir="auto">According to law enforcement, the suspects are accused of deploying malicious code through legitimate software packages, compromising developer environments to inject backdoors into widely used libraries. The attacks targeted the software supply chain, meaning that organizations relying on the compromised packages were indirectly infected when they updated their dependencies.</p>
<ul>
<li>The suspects face charges related to unauthorized access, data theft, and the deployment of malware.</li>
<li>The investigation involved coordination between Australian federal police and international cybersecurity agencies.</li>
<li>Authorities have not yet disclosed the full extent of the damage, but previous reports linked TeamPCP to campaigns affecting numerous open-source projects.</li>
</ul>
<p dir="auto">Technical analysis of the attacks shows a focus on persistence, with the malicious code designed to resist removal and evade detection by standard security tools. The group’s methods included typosquatting, dependency confusion, and direct compromise of maintainer accounts.</p>
<p dir="auto">While the full list of affected packages has not been published, organizations using popular open-source libraries are advised to audit their dependencies and check for suspicious updates over the past year.</p>
<p dir="auto"><em>The individuals have been released on bail and are scheduled to appear in court at a later date.</em></p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/australia-arrests-alleged-teampcp-hackers-behind-supply-chain-attacks" target="_blank" rel="noopener noreferrer nofollow ugc">Unknown</a></p>
<p dir="auto">Given the focus on developer environments, has your team reviewed your dependency lockfiles and maintainer account security in light of this disclosure?</p>
]]></description><link>https://xploitlk.com/topic/125/australia-arrests-alleged-teampcp-hackers-behind-supply-chain-attacks</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:37:25 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/125.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 28 Aug 2026 00:30:24 GMT</pubDate><ttl>60</ttl></channel></rss>