Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Two men from Western Australia have been charged in connection with TeamPCP, a cybercriminal group responsible for a global supply-chain hacking campaign that targeted over 1000 organizations, including OpenAI and the European Commission. The group used a self-propagating worm, Shai-Hulud, to steal data and credentials, compromising open-source software packages and leading to significant data breaches and extortion attempts.
Police in Australia have charged two men from Western Australia over their alleged involvement with TeamPCP, a cybercriminal group linked to a widespread software supply-chain attack. The Australian Federal Police (AFP), in collaboration with the FBI and Western Australia Police, announced the charges on August 26th, accusing the men of data intrusion and unauthorized modification of data. According to authorities, the two men were key members of a sophisticated cybercrime syndicate that created malicious open-source software designed to steal data and demand ransom payments from businesses.
TeamPCP gained notoriety for its Shai-Hulud worm, a self-propagating malware that exploited open-source software repositories like GitHub and NPM. The worm hijacked developer credentials and published boobytrapped versions of legitimate packages, effectively infecting users and their software. This allowed the group to compromise thousands of victims simultaneously.
Several high-profile breaches were linked to TeamPCP, including the compromise of vulnerability scanner Trivy, leading to breaches of open-source AI gateway LiteLLM, and AI recruitment firm Mercor. The group even directly compromised LiteLLM's own code, harvesting secrets from over 2,500 organizations. Notably, TeamPCP’s activities resulted in the theft of data from OpenAI and a hack of the European Commission’s cloud infrastructure.
Adding a disturbing element, the group ran a competition on Telegram, offering a prize to anyone who could build the largest attack using Shai-Hulud code. This highlights the group's deliberate strategy of exploiting trust in widely-used open-source software packages. The attacks underscore the critical need for developers to rigorously vet open-source components and implement robust security practices.