Key points
- The NDIA says multi-layered security controls stopped hackers calling themselves TeamPCP from exploiting its systems during a March supply chain attack.
- Security vendor Hudson Rock obtained a 153 gigabyte archive in August containing NDIA-related credentials.
- TeamPCP compromised Trivy, an open source vulnerability scanner from Aqua Security, swapping in malicious code behind existing release numbers to harvest build system credentials.
The National Disability Insurance Agency (NDIA) is crediting its multi-layered defences for seeing off a software supply chain attack in March this year.
Hackers calling themselves TeamPCP went on a supply chain attack spree then, compromising developer credentials with malware at thousands of organisations worldwide, including the NDIA.
If not reset, the compromised credentials could be used for further unauthorised access, and to spread more malware.
A National Disability Insurance Agency (NDIA) spokesperson confirmed the attack to iTnews.
The spokesperson stressed that "no protected, sensitive, or participant information was accessed or compromised."
"When this activity occurred in March 2026, the NDIA identified it within hours and acted immediately, including undertaking reset and recovery actions," the spokesperson said.
The spokesperson said NDIA continually monitors and reviews its cyber security environment and takes appropriate action to respond to emerging threats.
"It was not possible for the threat actor to exploit NDIA systems as a result of the multiple layers of security controls that we employ," the spokesperson said.
Large amounts of credentials leaked
While the supply chain attack took place in March this year, NDIA-related information was found in a large, 153 gigabyte archive that security vendor Hudson Rock said it had obtained and published this August.
The security vendor has set up a lookup tool for the data, in which NDIA appears, along with 2488 corporate domains such as Amazon Web Services, Samsung, Cisco, Salesforce, Deloitte and ServiceNow.
In technical terms of what TeamPCP stole, Hudson Rock's entry for NDIA records 175 leaked continuous integration (CI) runner dumps.
Each of these is a capture of the environment in which a single automated software builds ran, and holds the required access credentials for the job.
The lookup tool names NDIA's GitLab instance, gitlab.apps.ndia.gov.au, along with 18 code repositories and 20 identities anonymised to a single character; 19 of them being agency staff addresses and one an apparent service account.
"Secrets" in the data set include 1225 JSON web tokens (JWTs) and 525 GitLab CI job tokens.
Much of that volume is repetitive, with the same credential appearing in several variables across each of the 175 runs, and almost all of it expired when the jobs finished.
The 354 entries classed as generic secrets comprise a single JFrog Artifactory registry credential repeated across 175 runs, a truncated GitLab runner identifier repeated the same number of times, and a small number of tokens for HashiCorp's Terraform infrastructure-as-code platform.
Those secrets would persist until manually revoked.
Hudson Rock's list includes Amazon Web Services, Samsung, Cisco, Salesforce, Deloitte and ServiceNow, with 2488 corporate domains altogether.
How the attacked worked
The TeamPCP supply chain campaign in question took place in March this year, with the hackers attacking Trivy, a popular open source vulnerability scanner from Aqua Security.
Stolen access credentials let the group swap in malicious code behind Trivy's existing release numbers, so even organisations that had pinned to only use a known-good version received the compromised one.
The compromised scanner then harvested credentials from the build systems that ran it, including those of the LiteLLM artificial intelligence gateway, whose own publishing credentials TeamPCP used to push malicious versions of that package.
TeamPCP has been active since early 2026, and conducted several high-profile attacks including compromising Microsoft-owned code-hosting platform GitHub in May.

Forrester's AI Forum Sydney
NiCE World APAC 2026
The 2026 iAwards
Integrate 2026
Security Exhibition & Conference



