Security
Cat videos, a HackerOne account, and a TikTok profile helped reveal the identities of alleged attackers.
Two men allegedly behind the hacking group responsible for attacks on thousands of open source packages and private GitHub repositories have been arrested in Australia, after an international investigation.
The Western Australia Police Force and FBI arrested two Australians aged 21 and 23 on Wednesday 26 August after an investigation launched after tips from private security researchers, and announced a combined 14 charges against them over alleged connections to the group TeamPCP.
Australian Federal Police (AFP) Commander Graeme Marshall said: “Our investigators are relentless in tracking down criminals who attempt to exploit digital anonymity to attack our community. In this matter, the information provided to authorities by a number of threat assessment companies proved crucial.”
TeamPCP is best known for a series of supply chain attacks dubbed “Shai Hulud” and “Mini Shai Hulud” in late 2025 and early 2026, hitting private GitHub repos and npm packages with tens of millions of downloads.
The two men, identified by local broadcaster ABC as Ruben Ian Thomson and Louis Michael Gaebler, were described as “masterminds” by prosecutors and will next appear in court on 18 September.
Prosecutors seized electronic devices from the pair and have already extracted 100TB of data. They said further charges are likely to be brought.
Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.
Already a member? Sign in