Two Perth men face court over TeamPCP open-source poisoning

Australian police charged two Western Australian men over the TeamPCP syndicate's open-source supply chain attacks.

CSBadmin
2 Min Read

The Australian Federal Police charged two Western Australian men over their alleged roles in TeamPCP, the syndicate behind March 2026 compromises of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM.

Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27 facing 14 combined charges, including unauthorized modification of data, possessing data with intent to commit computer offences, and dealing in proceeds of crime. Police searched homes in Cottesloe, Hamilton Hill, and Mandurah the previous day and seized electronic devices for forensic analysis.

The FBI says TeamPCP’s malicious code potentially compromised more than a thousand organizations worldwide. A July 2 FBI advisory warned that credentials and data stolen in the campaign remain a persistent risk and urged affected firms to rotate CI/CD secrets, publishing tokens, and cloud credentials exposed during the intrusion windows.

TeamPCP emerged in late 2025, poisoning open-source packages and extorting victims. Its self-propagating Shai-Hulud worm stole developer credentials to push malicious code into widely used tools, a cycle researchers have described as the longest-running software supply chain attack spree on record. The arrests mark the first public criminal charges against the group’s alleged principals.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.