WA Charges Highlight a New Software Supply Chain Threat
Two Western Australian men have been charged over their alleged involvement in TeamPCP, a cybercrime group accused of compromising trusted open-source software used by organisations around the world.
The Australian Federal Police (AFP), working with the Western Australia Police Force (WAPF) and the US Federal Bureau of Investigation (FBI), charged the two men with a combined 14 offences following a joint investigation into the alleged cybercrime syndicate.
Police allege the group used malicious code inserted into open-source software to gain access to other organisations. More than 1,000 organisations could have been affected, with investigators estimating that more than 500,000 credentials were stolen and at least 300GB of data exfiltrated. Global remediation costs are estimated to have reached hundreds of millions of dollars.
The investigation began in April 2026 after cyber threat assessment companies provided information to the AFP and FBI. Search warrants were subsequently carried out in Cottesloe, Hamilton Hill and Mandurah, with electronic devices seized for forensic examination. The investigation remains ongoing and further charges have not been ruled out.
What makes the case particularly notable is the software TeamPCP allegedly targeted.
Technical analysis by Palo Alto Networks' Unit 42 found that the group compromised widely trusted security and development tools, including Trivy, a vulnerability scanner, Checkmarx KICS, which scans infrastructure-as-code, and LiteLLM, an open-source AI gateway. The attackers were able to inject malicious code into legitimate software distribution channels, meaning users could download compromised versions as part of otherwise routine development and security processes.
According to Unit 42, the compromised tools could expose sensitive information including cloud credentials, SSH keys and Kubernetes secrets. The researchers described the campaign as effectively "weaponizing the protectors", because security tools themselves became part of the attack route.
The incident highlights a wider challenge for organisations that rely on software supplied by third parties. Security teams can have extensive controls around their own networks, but malicious code entering through a trusted dependency can create a very different type of risk.
For organisations operating security technology and critical infrastructure, the issue extends beyond traditional IT systems. Modern security platforms, connected devices and other technologies increasingly rely on software components and third-party dependencies, making visibility of the wider technology supply chain an important part of security planning.
The Australian case also demonstrates how international cybercrime investigations can have a distinctly local starting point. The AFP says the two men allegedly played a principal role in a syndicate whose activity affected organisations globally, while cooperation between Australian and US authorities was central to the investigation.
The charges are now before the Australian courts, with investigations continuing. But the case has already raised a wider question for organisations: how much do they know about the software and suppliers they rely on to keep their systems secure?
ICYMI Australian News: Coles and Woolworths put facial recognition back under the spotlight
Register for The Security Event Australia happening 25-26 November 2026, MCEC Melbourne
Subscribe to The Security Briefing for monthly updates!
