Technology and AI
Two men are charged over code placed in an open repository that reached more than a thousand organisations and half a million credentials
By Staff Writer | 29 August 2026

Australian and American investigators say malicious code inserted into software on an open source repository was pulled in by other developers and carried into government, university and private systems. Fourteen charges have been laid against two men, one of them carrying a maximum of twenty years. Remediation across the affected organisations is put in the hundreds of millions of dollars.
The mechanism is the part to understand, because it is the one every organisation with a software supply chain is exposed to. Police allege that a syndicate put malicious code into software published on an open source repository. Other developers, having no reason to think anything was wrong with it, pulled that software into their own projects. Those projects were then distributed into computer systems across government, academia and the private sector, and the code inside them allowed the group to reach in and harvest sensitive material, including user credentials and authentication tokens. Nobody had to be attacked. They only had to build.
The arithmetic that follows is the reason this is not a niche story. More than a thousand organisations worldwide were potentially compromised. More than 500,000 credentials were taken. At least 300 gigabytes of data left. Remediation across the affected organisations, so far, is estimated in the hundreds of millions of dollars. All of that came from what the investigators describe as the compromise of a small number of trusted software components.
What was charged
Two West Australian men were charged on 26 August with a combined fourteen offences, after search warrants were executed the same day at properties in Cottesloe, Hamilton Hill and Mandurah. Devices and other items were seized for forensic examination. Both were listed to appear in the Perth Magistrates Court the following day.
A 21 year old man from Cottesloe faces one count of possessing data with intent to commit a computer offence, four counts of unauthorised modification of data with intent to commit a serious offence, one count of supplying data with intent to commit a computer offence, one count of failing to comply with an order to assist under section 3LA of the Crimes Act 1914, which carries ten years, and one count of dealing with proceeds of crime worth 100,000 dollars or more, which carries twenty. A 23 year old man from Mandurah faces the first three of those, without the assistance order or the proceeds count. Police allege both were principal participants and were paid in cryptocurrency, in amounts still being worked out.
Cybercrime syndicates are becoming increasingly organised and often operate like professional businesses, but our investigators are relentless in tracking down criminals who attempt to exploit digital anonymity to attack our community.
Graeme Marshall, Commander, Australian Federal Police
Who found it, and how
Not the victims. The parallel investigations began in April, after the Australian and American agencies were given information by several cyber threat assessment companies. The commander leading the Australian side said in terms that the information those companies provided was what made the investigation possible, and that early reporting and sustained cooperation between organisations and law enforcement do the work in cases of this kind. That is worth reading as an instruction rather than a courtesy: the detection came from outside the compromised organisations, which is another way of saying that most of the thousand did not know.
The Western Australian force put the domestic point more plainly, noting that the disruption shows how common this offending has become and that those committing it live in the same suburbs as everybody else. Its advice to businesses was to report incidents whatever their size, because a police force that cannot see the pattern cannot seize the evidence.
A large volume of seized data is still being examined and the investigation continues. Further arrests and charges have not been ruled out.