Two Charged Over TeamPCP Campaign
The Australian Federal Police (AFP) has charged two Western Australian men over their alleged role in TeamPCP, the cybercrime group blamed for the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS, along with the AI gateway LiteLLM. The pair appeared before Perth Magistrates Court on August 27, 2026.
The Defendants
- Louis Michael Gaebler, 23, of Mandurah — charged with five offences: possessing data with intent to commit a computer offence, four counts of unauthorized data modification with intent to commit a serious offence, and supplying data with intent to commit a computer offence.
- Ruben Ian Thomson, 21, of Cottesloe — charged with six offences, including the same core computer-crime counts as Gaebler, plus failing to comply with a section 3LA order (compelling disclosure of access information) and dealing with proceeds of crime worth over $100,000.
What TeamPCP Is Accused Of
Investigators allege TeamPCP stole publishing credentials and pushed poisoned package versions through GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX as part of a supply chain campaign that hit widely used developer tooling — including the Trivy and Checkmarx KICS security scanners and the LiteLLM AI gateway.
The AFP alleges the campaign compromised more than 1,000 organizations globally, exfiltrated over 300 GB of data, and harvested more than 500,000 credentials.
Charges and Potential Penalties
Section 3LA non-compliance carries a maximum penalty of up to 10 years' imprisonment, while the proceeds-of-crime charge carries up to 20 years. The unauthorized data modification counts each carry substantial custodial penalties under Australian computer crime law.
Why It Matters
TeamPCP's targeting of security scanners and CI/CD tooling rather than end applications is consistent with a broader 2026 trend: attackers compromising the software supply chain at its most trusted layer — the tools developers use to find vulnerabilities — to maximize downstream reach across thousands of dependent projects. The arrests mark one of the more concrete law enforcement outcomes so far this year against a group tied to the wave of npm, PyPI, and CI/CD supply chain incidents that dominated the security news cycle throughout Q1 2026.
What's Next
Both men remain before the courts, with the case now proceeding through the Western Australian judicial system. The AFP has not indicated whether additional suspects are being sought in connection with the broader TeamPCP campaign.