Security2 distinct publishers2 min readPublished
Two Western Australians face 14 charges over the March compromise of Trivy, KICS and LiteLLM, but the credentials that campaign harvested remain tradeable, so the FBI's order to rotate every exposed CI/CD secret stands.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Rotation is load-bearing here because the campaign ran on credentials rather than exploits. TeamPCP took publishing credentials from trusted open-source projects and pushed poisoned versions out through those projects' own release channels, across GitHub Actions, Docker Hub, npm, PyPI and OpenVSX [10]. Each compromise paid for the next: credentials stolen from Trivy were turned on Checkmarx KICS actions days later [11].
LiteLLM's own build pipeline installed Trivy without pinning it to a verified version, so the poisoned scanner harvested LiteLLM's publishing token, and the actor used that token to push backdoored LiteLLM releases in late March [c12a]. LiteLLM routes requests across LLM providers, which is where an organization's provider keys are consolidated [c12b]. Anything a poisoned build could read while it executed was reachable, so the token list runs wider than the artifact list [c12a].
Hudson Rock attributed 118,829 CI runner dumps to 2,488 corporate domains, taken from a 153GB archive of the attackers' own exfiltrated data [16]. Divide it out: roughly 48 runner dumps per affected domain [1]. That ratio makes cleanup a per-pipeline exercise.
The police figures are not independent of vendor telemetry. Unit 42 published the same two figures in March, hedged as what the actor "may have exfiltrated" [14], and FBI Cyber Division Assistant Director Brett E. Leatherman used the same order of magnitude, saying the malicious code "potentially compromised more than a thousand organizations worldwide" [5]. SecurityWeek reports the group deployed the Mini Shai-Hulud worm, and likely the original, to automate credential theft and self-propagation across package registries [22].
The charge sheet is narrower than the campaign. The Cottesloe man, 21, faces one count of possessing data with intent, four counts of unauthorized modification, one count of supplying data, one count of failing to comply with a section 3LA order, and one count of dealing with proceeds of crime worth $100,000 or more [6]. The Mandurah man, 23, faces six counts and no proceeds count [7]. The 3LA offence carries a 10-year maximum, the proceeds count 20 years [8]. SecurityWeek puts Thomson's exposure at 3 to 20 years per charge and Gaebler's most serious counts at a five-year maximum [21], and describes losses attributed to the syndicate in the hundreds of millions of dollars [24]. Police allege both men were principal participants paid in cryptocurrency, in amounts still being worked out [3].
The seized devices are what could turn reconstructed exposure into named victims. The AFP says the forensic examination continues and that further arrests and charges have not been ruled out [20].
Ranked by verification strength, evidence, and original report placement.
The Australian Federal Police charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM.
Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27, 2026, a day after the AFP and Western Australia Police Force executed search warrants at properties in Cottesloe, Hamilton Hill and Mandurah and seized electronic devices for forensic analysis.
Police allege the two men were principal participants in the syndicate and received payments in cryptocurrency, the value of which is still under investigation.
In a July 2 advisory the FBI said organizations impacted by the campaign should treat exfiltrated data and credentials as a persistent risk, since affiliated threat actors are "likely to weaponize them long after the initial compromise", and advised rotating all CI/CD secrets, publishing tokens and cloud credentials accessible during the exposure windows.
FBI Cyber Division Assistant Director Brett E. Leatherman said in a joint media release that the two men are allegedly members of TeamPCP, whose malicious code "potentially compromised more than a thousand organizations worldwide".
The syndicate stole publishing credentials from trusted open-source projects and pushed poisoned versions out through the projects' own release channels; the campaign spanned five distribution ecosystems: GitHub Actions, Docker Hub, npm, PyPI and OpenVSX.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named charges plus first-party artifact check, but most detail rests on one publisher
Both publishers independently confirm the arrests, named defendants, the 500,000-credential and 300GB/1,000-organization figures, and worm-driven registry propagation, and the enforcement record is concrete (court appearance, itemized counts, statutory maxima). The Hacker News adds a verifiable first-party PyPI check and named third-party datasets. Evidence is capped short of high because the charge-allocation and sentencing-exposure accounts conflict between the two reports, the aggregate loss figure is unattributed, and most technical detail exists in only one source.
Multi-ecosystem exposure measured by several parties, confirmed compromise far narrower
Reach is documented from more than one direction: five distribution ecosystems, CloudSEK's >2,500 organizations and ~434,000 pipelines, Hudson Rock's 118,829 runner dumps across 2,488 domains from the attackers' own 153GB archive, and StepSecurity's per-platform split showing GitLab ahead of GitHub Actions. The toolkit remains in live use, with the framework open-sourced in May and a fresh npm wave on 4 August. The score is held below the exposure headlines because only 16 victims are confirmed on the leak site and CloudSEK itself warns credential theft is not proof of compromise.
Official and vendor scale numbers run ahead of confirmed compromise; the reporting flags the gap
Headline framing leans on potential rather than verified impact: the AFP and FBI use 'potentially compromised' for >1,000 organizations, Unit 42's identical figures were hedged as what the actor 'may have exfiltrated', and SecurityWeek's hundreds-of-millions loss figure is unattributed, all against 16 confirmed leak-site victims. The gap is modest rather than large because the cluster surfaces its own caveats, and one under-covered fact runs the other way: the malicious LiteLLM builds are still fetchable from PyPI's CDN, an ongoing exposure neither publisher's headline claims.
Law-enforcement announcement plus commercially interested exposure vendors
The primary material is a joint AFP/FBI media release issued alongside charges, where emphasizing global scale serves the agencies' announcement, and the quantitative exposure numbers come from security vendors that sell related detection and CI/CD hardening services (CloudSEK, Hudson Rock, StepSecurity, Unit 42, Oligo, Socket). Countervailing signals exist: CloudSEK publicly discounts its own dataset as proof of compromise, and one publisher performed an independent artifact check rather than relying on vendor claims.
Solid on the enforcement and remediation core, weaker on damages and charge allocation
The arrests, the attack chain, the ecosystem spread and the standing rotation requirement are well supported and mutually consistent across two publishers plus named third-party datasets, and the freshest facts are same-day. Confidence is reduced by the direct conflict between the publishers on which defendant faces which offences and penalties, the unattributed loss estimate, and reliance on a single publisher for nearly all technical and dataset detail.
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
build
56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet1 distinct publisher
security
AFP arrests two Western Australians tied to the Shai-Hulud supply chain spree1 distinct publisher
build
Flux moves GitOps' source of truth into registries you own, and mirroring becomes the prerequisite1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
1 article · August 27, 2026