TeamPCP is a cybercrime group alleged to have compromised open-source projects like Trivy, Checkmarx KICS, and LiteLLM in March 2026. The group stole publishing credentials and pushed poisoned releases, affecting over 1,000 organizations globally. Two alleged members were charged in Australia.