Security1 distinct publisher2 min readPublished Updated
Two suspects in Western Australia are in custody over the supply-chain worm that hit Trivy, KICS, LiteLLM and Telnyx. The 500,000 credentials it harvested stay valid until someone rotates them. Only 78,000 have surfaced publicly.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The worm's spread never depended on the operators. It sat inside a package until it was installed on a developer's machine, took the credentials stored there, then wrote itself into other open-source libraries that developer maintained [6]. Each infected maintainer became a publisher. A remand hearing in Perth [2] cannot recall code already sitting in package trees, and cannot un-steal credentials exfiltrated months ago.
The numbers set the scope of the clean-up. Authorities count more than 500,000 credentials taken [7]. The dump that surfaced last month held more than 78,000 tokens and secrets from almost 2,200 organisations [8]. That is about 16 percent of the counted total [1], averaging roughly 35 secrets per organisation named in it [2], and it leaves on the order of 422,000 credentials that were collected and never published [3]. Searching the leaked file for your own domain is a test with 16 percent coverage.
Lineage matters for how this campaign gets read. Oligo, in an investigation published earlier this month, matched TeamPCP infrastructure and tradecraft to a 2020 crypto-mining botnet that hit cloud servers, and concluded the members would have been teenagers when they started [9]. That is a six-year progression from stealing other people's CPU cycles to holding maintainer access in four named open-source projects [5], done by the two people the AFP arrested on Wednesday [1].
The attribution trail was open longer than the arrest date suggests. The AFP investigation began in April, with the FBI involved [10]. CyberScoop reported in June that Google had traced TeamPCP activity to residential and mobile IP addresses in South Africa [11]. WAToday reports Thomson was born in South Africa and had recently travelled there [12], which reads as a personal link rather than an operating base. Brian Krebs had also identified Thomson without much difficulty, according to Risky Business [13]. A man operating out of suburban Western Australia ran a campaign that produced ransomware and extortion cases at major companies and government organisations [15]. His name was circulating among reporters before it ever reached a courtroom.
One element here is inference rather than record. Risky Business raises the possibility that the credential dump was an attempt to muddle attribution as pressure built, and says plainly it is unclear whether the pair sensed law enforcement closing in [14]. The arrests, the charges and the refusal of bail are on the record [1][2][4], while the motive for the dump remains unconfirmed.
Ranked by verification strength, evidence, and original report placement.
The Australian Federal Police arrested two suspects believed to be part of the TeamPCP hacking group on Wednesday, detaining them in Cottesloe and Mandurah, near Perth in Western Australia.
The two suspects appeared in front of a Perth magistrate to be charged on Thursday.
According to local media, the suspect arrested in Cottesloe was identified as Ruben Thomson, 21, the group's alleged leader, and the Mandurah man as Louis Gaebler, 23.
Both suspects remain in custody after the judge refused Thomson's bail request; Gaebler did not apply for bail.
The two are accused of carrying out multiple software supply-chain attacks earlier this year, with their most successful incidents including the compromises of open-source projects Trivy, KICS, LiteLLM and Telnyx.
The group operated by hacking open-source coding libraries and adding a self-spreading worm; the worm hid until the library was installed on a developer's machine, then activated to steal credentials stored on that system and add itself to other open-source libraries the infected developer managed.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One bulletin, borrowed throughout
Risky Business is the only outlet we hold on this, and it is candid about where each piece came from: names from local media, the 2020 lineage from Oligo, the South African IP trail from CyberScoop in June, the travel detail from WAToday and its own sources. The arrest and the court appearance are the kind of facts that hold up because they are checkable in a Perth registry; the 500,000-credential figure is a police number reproduced without a document behind it. Sober relaying is not the same as verification.
Real blast radius, unnamed victims
The four compromised projects are specific and checkable — Trivy and KICS sit inside CI pipelines, LiteLLM inside AI stacks — and the leaked file gives roughly 2,200 organizations something concrete to grep their own secret stores for. That is genuine, measurable reach. Against it: the harm side of the story is entirely generic, and the arithmetic says only about a sixth of the credentials police count have ever been seen outside the investigation.
Scale outruns what anyone can see
Nothing in the writing is breathless — the tone is a police blotter. The gap opens between the two numbers the story puts side by side: a half-million credentials, attributed to authorities and untested, and 78,000 that actually surfaced. Arrests also invite a sense of resolution the facts do not support, since custody in Perth does not expire a single stolen token. The overstatement is structural, not rhetorical.
Disclosed sponsor, flattering police math
The bulletin opens by naming its sponsor, Push Security, a vendor selling into precisely the credential-theft problem the story describes — disclosed, not concealed, and the story would exist without it. The stronger pull sits upstream: scale figures released alongside an arrest make the arrest look bigger, and the AFP supplied both the 500,000 count and the April start date. Neither pressure proves distortion; both are reasons the half-million wants checking by someone with nothing to sell.
Solid on the arrest, thin on the scale
Two things here are firm: two named men are in custody in Western Australia over these compromises, and a public dump exists that security teams can test against their own environments. Everything about magnitude, lineage and downstream damage sits one relay removed, and the only speculative passage is labelled as such by the writer. Enough to act on this morning; not enough to quote as settled next quarter.
product
Flare traced TeamPCP's GitHub handle to a HackerOne profile carrying a real name1 distinct publisher
security
Jackal IV's 58 arrests cover under a third of the suspects INTERPOL identified1 distinct publisher
science
TeamPCP hid its infostealer inside the scanners that audit everyone else's code1 distinct publisher
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026