The Australian Federal Police have charged two men in connection with the TeamPCP cybercrime group, responsible for compromising critical open-source security tools like Trivy and Checkmarx KICS.
- Two men from Western Australia face 14 charges related to the TeamPCP cybercrime group.
- The attacks targeted critical open-source tools including Trivy, Checkmarx KICS, and LiteLLM.
- The compromise occurred in March 2026, impacting global software supply chains.
In a significant crackdown on cyber criminality, the Australian Federal Police (AFP) has charged two men from Western Australia following their alleged involvement with the TeamPCP cybercrime group. The suspects, identified as Louis Michael Gaebler (23) and Ruben Ian Thomson (21), appeared in the Perth Magistrates Court on August 27.
The charges stem from a series of sophisticated attacks in March 2026 that targeted the very foundations of modern software security. The group is accused of compromising Trivy and Checkmarx KICS—two widely used open-source security scanners—as well as LiteLLM, a prominent AI gateway. This compromise allowed for potential unauthorized access and vulnerabilities to be introduced into countless software projects worldwide.
Why This Matters
BozokMedia analysis shows that this incident represents a high-tier supply chain threat. By targeting security scanners, the attackers essentially attempted to 'blind' the tools that developers use to detect vulnerabilities. This creates a cascading effect where the software built using these tools is inherently compromised from the start.
Targeting the security infrastructure itself is the most efficient way for modern threat actors to achieve massive, undetected scale.
The legal proceedings against Gaebler and Thomson involve a combined total of 14 offences. As investigators delve deeper, the focus remains on whether this was an isolated criminal act or part of a larger, more coordinated international effort to undermine digital trust.
Historical Background
Supply chain attacks have become a preferred method for high-level hackers. By infiltrating a single trusted vendor or open-source repository, attackers can gain access to thousands of downstream customers. Notable historical examples include the SolarWinds breach, which demonstrated how a single compromised update could impact government agencies and global corporations alike.
Frequently Asked Questions
1. What is a supply chain attack?
It is a cyberattack that targets less secure elements in a supply network to reach a larger, more secure target, such as compromising a software tool used by many companies.
2. Which tools were affected by TeamPCP?
The primary tools compromised included the security scanners Trivy and Checkmarx KICS, along with the AI gateway LiteLLM.