Two Perth men charged over TeamPCP hack that hit OpenAI and GitHub Australian Federal Police arrested Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, in Perth on August 26, charging them over TeamPCP, a supply-chain attack that compromised more than 1,000 organizations, exposed over 500,000 credentials, and exfiltrated at least 300GB of data, with remediation costs in the hundreds of millions of dollars. The syndicate injected malicious code into trusted developer tools including Aqua Security's Trivy, Checkmarx's KICS, and LiteLLM versions 1.82.7 and 1.82.8, affecting downstream victims such as OpenAI, GitHub, and the European Commission. Australian police have charged two Perth men over TeamPCP, the supply-chain crew accused of poisoning trusted developer tools and exposing more than 500,000 credentials across more than 1,000 organizations. Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, are now the local faces of a global software-supply-chain case that should make every engineering team check what its build system trusts. The Australian Federal Police arrested the men on August 26 after raids in Cottesloe, Hamilton Hill and Mandurah, working with Western Australia Police and the FBI. Thomson faces eight charges, including four counts of unauthorized data modification, failing to comply with an order to hand over device passwords, and dealing in criminal proceeds worth $100,000 or more. Gaebler faces six related counts. Both appeared in Perth Magistrates Court the next day, according to ABC News and The Record from Recorded Future News. How the campaign spread Police allege Thomson and Gaebler were principal participants in TeamPCP, a syndicate accused of putting malicious code into open-source software that developers then pulled into their own systems. That is the ugly part. The attackers did not need to break into every company one by one. The March campaign hit tools that sit close to the keys. Wiz tracked the first wave to March 19, when malicious code was injected into Aqua Security's Trivy vulnerability scanner and related GitHub Actions. Arctic Wolf later said the attackers had stolen CI/CD secrets and deleted trusted tags, then force-pushed malicious binaries beginning with Trivy v0.69.4. On March 23, Wiz reported that Checkmarx's KICS GitHub Action had also been compromised. A day later, Endor Labs reported that LiteLLM versions 1.82.7 and 1.82.8 on PyPI carried credential-stealing code that was not present in the upstream GitHub repository. If you run CI/CD pipelines, you should pause on that sequence. Trivy is meant to find weaknesses, and KICS scans infrastructure-as-code. LiteLLM sits in AI stacks where OpenAI, Anthropic and other provider keys may be stored. TeamPCP went after the tools teams use to tell themselves they are secure. Hackers Just Showed How Fragile the AI Software Supply Chain Really Is https://startupfortune.com/hackers-just-showed-how-fragile-the-ai-software-supply-chain-really-is/ A March 2026 supply chain attack on LiteLLM, the AI gateway used by thousands of companies to route traffic to OpenAI, Anthropic, and other providers, exposed how privileged and fragile the AI software stack has become. New research from Booz Allen and Andreessen Horowitz shows the deeper problem: model backdoors that survive safety training and... - AI supply chain security vulnerabilities https://startupfortune.com/hackers-just-showed-how-fragile-the-ai-software-supply-chain-really-is/ - LiteLLM package poisoning attack 2026 https://startupfortune.com/hackers-just-showed-how-fragile-the-ai-software-supply-chain-really-is/ The AFP said the malicious code potentially compromised more than 1,000 organizations globally. It enabled the theft of more than 500,000 credentials and led to the exfiltration of at least 300GB of data. The agency put global remediation costs in the hundreds of millions of dollars. TechCrunch reported that affected or targeted organizations included Mercor, the European Commission, GitHub and OpenAI, while The Record noted the European Commission and GitHub among downstream victims. Those names matter, but the mechanism matters more. TeamPCP did not need OpenAI or GitHub to make a foolish public mistake. It needed a trusted tool, a movable tag, a stolen token and a build system ready to run whatever looked legitimate. That's enough. The weak point was trust Endor Labs said the LiteLLM compromise used PyPI publishing tokens stolen after LiteLLM's pipeline ran a poisoned Trivy dependency. The attackers then pushed rogue LiteLLM releases, version 1.82.7 and 1.82.8, only 13 minutes apart. Version 1.82.8 added a .pth file, which can run when the Python interpreter starts, even if a developer never imports LiteLLM directly. That is not a small technical detail. It changes the blast radius. Here's the thing: plenty of serious teams still pin GitHub Actions to tags instead of full commit hashes. A tag feels fixed because it has a version number. It isn't fixed if someone with the right access can move it. The TeamPCP campaign turned that gap into a credential harvester, and it worked against security-adjacent projects with real engineering teams behind them. The AFP said its investigation started in April 2026 after the agency and the FBI received information from multiple cyber threat assessment companies. Investigators later linked the two WA men to the syndicate and seized a large volume of data for forensic examination. ABC News reported that police had already extracted 100 terabytes of data from devices seized from one address and expected to extract more. Thomson also faces a charge for failing to comply with a section 3LA order to provide device passwords. That does not prove what is on the hardware, and neither man has entered a plea. The presumption of innocence still matters. But it does show investigators believe the seized devices are important to the case. For engineering teams, the immediate lesson is plain enough. Audit Trivy, KICS and LiteLLM exposure in March. Rotate any secret that touched those pipelines. Stop treating a version tag as an immutable control. TeamPCP's alleged operators were young men in Western Australia, not a giant state-backed unit with unlimited resources. If the AFP's case holds up, that is what makes the damage harder to ignore. TeamPCP shows why trusted developer tools are now the target https://startupfortune.com/teampcp-shows-why-trusted-developer-tools-are-now-the-target/ TeamPCP’s attacks show how poisoned developer tools can turn trusted open source workflows into entry points for major breaches. The GitHub incident is current evidence that developer machines, extensions and package ecosystems now sit at the center of business risk. - why developer tools have become security targets https://startupfortune.com/teampcp-shows-why-trusted-developer-tools-are-now-the-target/ - how attackers compromise popular developer tool extensions https://startupfortune.com/teampcp-shows-why-trusted-developer-tools-are-now-the-target/ Also read: SoftBank Is Negotiating to Buy Majority Control of Humanoid Maker 1X at a $6 Billion Discount https://startupfortune.com/softbank-is-negotiating-to-buy-majority-control-of-humanoid-maker-1x-at-a-6-billion-discount/ • Thousands Order AI Companion Robots as UBTech's U1 Hits the Market https://startupfortune.com/thousands-order-ai-companion-robots-as-ubtechs-u1-hits-the-market/ • Pimco Warns AI Debt Issuance Is Growing Too Fast For Bond Markets https://startupfortune.com/pimco-warns-ai-debt-issuance-is-growing-too-fast-for-bond-markets/