The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged involvement in TeamPCP, the cybercrime group linked to the March 2026 supply chain attacks targeting the open source security scanners Trivy and Checkmarx KICS, as well as the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared before Perth Magistrates Court on 27 August 2026, following search operations conducted a day earlier by AFP and Western Australia Police Force at properties in Cottesloe, Hamilton Hill, and Mandurah. During the operation, investigators seized electronic devices for forensic examination. Authorities allege the two men played significant roles within the group and received cryptocurrency payments, with the total value of those transactions still under investigation.
According to investigators, TeamPCP carried out a sophisticated software supply chain campaign by obtaining publishing credentials from trusted open source projects and using them to distribute modified software through legitimate release channels. The attacks affected multiple software distribution ecosystems, including GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX. Investigators stated that credentials obtained from one compromised project were subsequently used to target additional projects. During the campaign, credentials taken from the Trivy security scanner were later used against Checkmarx KICS. LiteLLM was also affected after its build pipeline installed an unverified version of Trivy, allowing the attackers to obtain publishing credentials that were later used to distribute modified LiteLLM releases. Because LiteLLM is widely used to manage connections between large language model providers, the incident raised concerns about the exposure of enterprise AI infrastructure and cloud credentials.
AFP stated that the campaign potentially affected more than 1,000 organizations worldwide, enabled the theft of over 500,000 credentials, and resulted in the exfiltration of at least 300 gigabytes of data. Additional security research published by CloudSEK and Hudson Rock estimated that exposure may have extended to nearly 2,500 organizations and more than 434,000 CI/CD pipelines, although researchers noted that credential theft alone does not confirm a successful compromise. StepSecurity also analyzed the exposed infrastructure and reported that GitLab accounted for the highest number of affected organizations, followed by GitHub Actions, Azure DevOps, Jenkins, Bitbucket Pipelines, and CircleCI. While only 16 confirmed victims had been identified on the group’s leak site as of late March, security researchers believe the campaign demonstrated the widespread risks associated with software supply chain attacks targeting development environments and automation platforms.
The investigation has also drawn attention to the long term risks created by compromised software publishing credentials. Earlier guidance issued by the FBI warned organizations impacted by the campaign to treat exposed credentials as an ongoing security risk and recommended rotating all CI/CD secrets, publishing tokens, and cloud credentials that may have been accessible during the compromise period. The advisory also recommended searching enterprise environments for repositories named “tpcp-docs” and “docs-tpcp” and pinning GitHub Actions workflows to verified commit SHA hashes instead of floating version tags. Open source intelligence research has further linked TeamPCP infrastructure to activity dating back to 2020, although researchers noted that it remains unclear whether this reflects a continuation of earlier operations or closely related threat actors. Authorities continue to investigate the case while examining the seized electronic evidence as part of the broader effort to understand the full scope of the campaign and its global impact.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.