Authorities arrest 2 alleged members of prolific hacking group TeamPCP

| Source: Ars Technica AI

Tags: TeamPCP, supply-chain-attack, LiteLLM, Trivy, cybersecurity, CI/CD

Australian Federal Police arrested two Western Australian men — facing 14 charges each — for participating in TeamPCP, which used the Shai-Hulud worm to infect 1,000+ organizations via supply chain attacks on CI/CD pipelines, compromising AI tools including LiteLLM and the Trivy vulnerability scanner.

Details

TeamPCP emerged in December 2025 and ran one of the most prolific supply chain attack campaigns in recent memory over nine months. Its core weapon, a worm called Shai-Hulud, spread virally through open source software by targeting CI/CD pipelines: once a package was infected, it attached itself to future updates and collected credentials from infected hardware's memory, which were then used to compromise more packages. Among the downstream victims were AI-adjacent tools including LiteLLM and the KICS security scanner, both infected after their developers ran compromised versions of the Trivy vulnerability scanner. The initial Trivy compromise alone resulted in the theft of terabytes of credentials and private data. Shai-Hulud used an Internet Computer Protocol canister for C2 — a blockchain smart contract mechanism that allowed rapid URL rotation to resist takedowns, with infected machines checking in every 50 minutes. Australian Federal Police arrested two men from Cottesloe and Mandurah, Western Australia. KrebsOnSecurity published an extensive investigation identifying both defendants and tracing the operational security mistakes — including lack of discipline uncommon for a group of this capability — that led to their exposure. For AI practitioners: any organization whose CI/CD pipelines ran Trivy or a downstream package during this nine-month window should audit for potential credential exposure, especially given LiteLLM's role in AI inference infrastructure.