World August 31, 2026 12:08 PM

Two Australian Men Charged in Alleged Campaign to Seed Malicious Code into Open-Source Tools

Authorities say the suspected activity may have exposed thousands of organisations worldwide and prompted a U.S. indictment

By Caleb Monroe
Share
Twitter Reddit Facebook LinkedIn

Australian authorities have charged two men accused of involvement in a hacking collective that injected malicious code into popular open-source software, potentially compromising more than 1,000 organisations and leading to the theft of over 500,000 credentials and more than 300 gigabytes of data. The Australian Federal Police worked in parallel with the FBI, which later announced a separate U.S. indictment against one of the men.

Two Australian Men Charged in Alleged Campaign to Seed Malicious Code into Open-Source Tools
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • Australian Federal Police charged two men with a combined 14 counts for alleged roles in TeamPCP, a hacking collective accused of inserting malicious code into popular open-source tools.
  • Authorities estimate the campaign potentially affected over 1,000 organisations worldwide, resulting in theft of more than 500,000 credentials and over 300 gigabytes of data; some victims were allegedly extorted.
  • The AFP conducted a parallel investigation with the FBI after receiving information from multiple unnamed cybersecurity threat assessment companies; the U.S. later indicted one suspect in the Northern District of California.

Australian law enforcement on Thursday lodged criminal charges against two men accused of taking part in a coordinated effort to tamper with widely used open-source software tools, a campaign investigators say affected thousands of companies around the world.

The Australian Federal Police (AFP) said the pair face a total of 14 charges tied to their alleged participation in TeamPCP, a hacking collective that reportedly inserted malicious code into commonly deployed software components to gain access to corporate systems. Some affected organisations were later targeted for extortion, according to a July advisory issued by the U.S. Federal Bureau of Investigation (FBI).

While the AFP did not publicly identify the suspects, the Australian Broadcasting Corporation named them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. In initial court appearances, representation and comment were limited: the lawyer who handled Thomson's first appearance, Nick Scerri, directed questions to Thomson's current attorney, Paul Holmes, who declined to comment. James Gatti, the lawyer for Gaebler, also declined to comment.

Investigators say the malicious modifications to open-source projects potentially impacted in excess of 1,000 organisations around the world. Police estimates indicate the campaign enabled the theft of more than 500,000 credentials and the removal of over 300 gigabytes of data.

The AFP said it opened a parallel investigation with the FBI in April after receiving information from several unnamed cybersecurity threat assessment firms. In a statement included in the AFP release, FBI Cyber Division Assistant Director Brett Leatherman said the bureau was "proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks." The FBI declined to offer additional comment.

Late on Thursday, the U.S. Attorney's Office for the Northern District of California announced it had filed an indictment in the United States against Thomson. The charges listed in the U.S. indictment include conspiracy to commit violations of the Computer Fraud and Abuse Act and obtaining information from a protected computer.

Industry analysts have described TeamPCP as a significant threat actor. Austin Larsen, a principal threat analyst with Google's Threat Intelligence Group, characterized TeamPCP on LinkedIn as "one of the most impactful threat actors of 2026," describing it as a peer community of skilled individuals oriented around a common center of gravity rather than a single unified group.


Context and implications

The allegations highlight vulnerabilities in software supply chains when widely used open-source components are targeted. The cross-jurisdictional nature of the investigation - with Australian and U.S. authorities coordinating and relying on intelligence from private cybersecurity firms - underscores the global dimensions of such incidents and the complexity of attributing and prosecuting supply-chain compromises.

Risks

  • Ongoing legal and investigative proceedings - outcomes and further charges remain uncertain, which could affect the timing and scope of enforcement actions and remedial measures; this impacts legal and cybersecurity services sectors.
  • The scale of the compromise and reported extortion raise ongoing risk of additional data exposure and follow-on intrusions for organisations that relied on the affected open-source components; this affects software vendors, cloud service providers, and corporate IT operations.
  • Reliance on intelligence from multiple unnamed cybersecurity firms introduces uncertainty about the completeness and attribution of the activity, complicating response coordination across jurisdictions and the market for threat intelligence services.

More from World

Two People Killed After Flash Flood Strikes Grand Canyon, Park Service Says Aug 31, 2026 Colombian government outlines $11 billion financing plan, schedules debt swaps for late 2026-2027 maturities Aug 31, 2026 Defense Says Shooter in Charlie Kirk Killing Should Not Face Death Penalty Aug 31, 2026 Severe Winter Storms Push Chile's July Copper Production to Lowest July Since 2011 Aug 31, 2026 Nigeria Posts Strongest Quarterly Expansion in Five Years as Oil Revenues Surge Aug 31, 2026