- The Australian Federal Police charged two Western Australian men with 14 offenses for their alleged role in the TeamPCP cybercrime group, which compromised open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM.
- The group used stolen credentials to push poisoned software releases across five distribution ecosystems, potentially affecting more than 1,000 organizations worldwide and exfiltrating over 500,000 credentials and 300 gigabytes of data.
- Payments to the accused were made in cryptocurrency, with the value still under investigation, and the FBI warned that exfiltrated credentials pose a persistent risk to affected organizations.
Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27, 2026, after the AFP and Western Australia Police Force executed search warrants in Cottesloe, Hamilton Hill, and Mandurah. Police allege the two men were principal participants in the syndicate and received payments in cryptocurrency, the value of which remains under investigation.
The syndicate operated by stealing publishing credentials from trusted open-source projects and pushing poisoned versions through the projects’ own release channels across GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX. The compromise of one project supplied credentials used against the next, with credentials from Trivy turned on Checkmarx KICS days later.
LiteLLM’s build pipeline installed Trivy without pinning it to a verified version, allowing the poisoned scanner to capture the project’s publishing token. The actor used that token to push backdoored LiteLLM releases in late March, routing requests across large language model providers where organization keys are consolidated.
The AFP said the malicious code potentially compromised more than 1,000 organizations globally, enabling the theft of more than 500,000 credentials and exfiltration of at least 300 gigabytes of data. The FBI issued a July 2 advisory stating that impacted organizations should treat exfiltrated data and credentials as a persistent risk, as affiliated threat actors are “likely to weaponize them long after the initial compromise.”
FBI Cyber Division Assistant Director Brett E. Leatherman said in a joint media release that the two men are allegedly members of TeamPCP, whose malicious code “potentially compromised more than a thousand organizations worldwide.” The charges include multiple counts of unauthorized data modification, possessing data with intent, and, for one man, dealing with proceeds of crime worth AUD 100,000 or more.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
