Threat Insight
Australian Arrests Allegedly Disrupt TeamPCP, but the Shai-Hulud Threat Persists
Two young cybercriminals from Perth, Western Australia, aged 21 and 23, have been arrested after being accused of being the masterminds behind TeamPCP, a cyber extortion group that is part of the English-language cybercrime community known as Hacker Com. [1]
TeamPCP was first observed in November 2025 and has been responsible for a campaign of sophisticated cyberattacks directed at software developers using the Shai-Hulud worm, which infects code repositories on code-sharing sites such as GitHub.
Assessment
With the arrest of these two individuals, it is likely that the remaining members of the group will stop using the TeamPCP brand, at least for a while. It is also possible that the arrests could lead to information that allows law enforcement to arrest more members of the group.
Even if TeamPCP is dissolved and most of its members are eventually arrested, this does not mean that the threat posed by Shai-Hulud and similar malware to software development is over. The members of TeamPCP have already released the source code for the worm on cybercrime forums.
References
[1] https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global
Stay ahead with cyber insights
Newsletter
Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.
Your current browser privacy settings may be preventing this form from loading properly. To continue, please allow cookies/tracking for this site or temporarily disable strict privacy protection, then refresh the page.
If you’re still experiencing issues, please contact us at hello@truesec.com