The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences for their alleged roles in TeamPCP, a cybercrime group behind the March 2026 compromise of open-source security scanners Trivy and Checkmarx KICS, and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27, 2026, following search warrants executed by the AFP and Western Australia Police Force.
The syndicate stole publishing credentials from trusted open-source projects and pushed poisoned versions through official release channels, spanning GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX. The attack chain began with the Trivy compromise, which led to the Checkmarx KICS actions compromise, and then the LiteLLM build pipeline installed a poisoned Trivy that stole LiteLLM’s publishing token, enabling backdoored releases. The campaign potentially compromised over 1,000 organizations globally, stole more than 500,000 credentials, and exfiltrated at least 300 GB of data.
The FBI advised organizations to treat exfiltrated data as a persistent risk and rotate all CI/CD secrets. CloudSEK and Hudson Rock reported higher exposure figures, with CloudSEK estimating over 2,500 organizations and 434,000 CI/CD pipelines, while Hudson Rock attributed 118,829 CI runner dumps to 2,488 corporate domains. StepSecurity analysis found GitLab was the most affected platform. TeamPCP-linked infrastructure has been traced back to 2020, with ties to activity tracked as TA-NATALSTATUS and IronErn. The group also open-sourced a worm framework used in the Mini Shai-Hulud campaign, which was later used in a fresh npm wave targeting keyv and cacheable packages.
CVEs: CVE-2026-58231
Attack groups: TeamPCP, TA-NATALSTATUS, IronErn
Malware: Mini Shai-Hulud
Companies: Australian Federal Police, Western Australia Police Force, Federal Bureau of Investigation, Unit 42, CloudSEK, Hudson Rock, StepSecurity, Oligo Security, Socket
Products: Trivy, Checkmarx KICS, LiteLLM, GitHub Actions, Docker Hub, npm, PyPI, OpenVSX, GitLab, Azure DevOps, Jenkins, Bitbucket Pipelines
Original source: thehackernews.com