The arrests took place in the Western Australian towns of Cottesloe and Mandurah, the Australian Federal Police (AFP) said in a statement. The two men, whose names were not officially released but were reported by KrebsOnSecurity following an extensive investigation, are alleged to have participated in cybercrimes for TeamPCP.
The group has vexed law enforcement and security personnel since it emerged in December, earning a reputation for persistent supply chain attacks. TeamPCP targeted organizations' CI/CD pipelines—systems used to rapidly develop, update, and deploy software—by lacing open-source software with malware that self-propagated from one package to another. These viral infections enabled the group to compromise over 1,000 organizations globally within nine months.
The AFP statement did not provide further operational details but confirmed the arrests were made in coordination with the FBI and the Western Australia Police Force. The charges cover 14 offenses, though specific counts have not been publicly detailed. The investigation into TeamPCP's activities continues, with authorities urging organizations to review their software supply chain security.