Australian Federal Police (AFP) has charged two men in Western Australia with cyber offences linked to the alleged TeamPCP hacking group. The suspects—aged 21 and 23—are accused of involvement in a series of software supply chain attacks that used malicious code inserted into open-source components and then used that access to target organizations globally. Sources describe the alleged campaign as unusually long-running.

Across outlets, authorities say they coordinated with US investigators to identify and pursue the defendants. The charges relate to TeamPCP’s alleged creation of malicious open-source software, which reportedly affected widely used security tools and enabled subsequent compromises, including incidents involving the Trivy and Checkmarx KICS scanners and an AI gateway identified as LiteLLM. The AFP reportedly does not publicly name the defendants in its initial statement, while one outlet notes additional investigative work connected to identifying a suspect’s identity earlier.

Outlets also emphasize the seriousness of the alleged conduct and the possibility of lengthy prison sentences if convicted, without detailing any plea or trial outcomes.