Live webinar · KELA Cyber Intelligence CenterTLP:CLEAR
The TeamPCP arrests, from the inside
The full story of how KELA supported law enforcement:
Trivy, Checkmarx KICS and LiteLLM fell in five days, the cascade ran for five more months, and in August two men were charged in Perth.
Five months after the March waves, the cascade was still producing victims across npm, PyPI and GitHub Actions. On 26 August 2026, the Australian Federal Police charged two men in Perth, working with the FBI and Western Australia Police Force, after receiving information from cyber threat assessment companies. This session walks the full arc, and what it changes about how you model trust in your own pipelines.
Date
Monday
August 31, 2026
Time
10:00 EST
16:00 CEST
Duration
45 min
incl. Q&A
Free · Live
Register here
Register for the live session.
Registered and can't attend? The recording goes to everyone on this list.
What you'll learn
Five things you'll leave with
Most supply chain attacks find a weak dependency. TeamPCP did something harder to defend against: it compromised the security tools that check the dependencies. Between March 19 and 24, 2026, the group poisoned Trivy, Checkmarx KICS and LiteLLM, and each compromise supplied the credentials for the next.
How the cascade actually worked. Wave by wave, from a service account compromise to 76 of 77 poisoned version tags to malicious releases on PyPI, and why the credential rather than the CVE was the payload.
Why an incomplete rotation was the whole story. A February 2026 breach was patched but not fully rotated. That single gap is what made March possible, and it is the most common version of this failure.
What "still running" looks like in practice. The compromises that landed after the March reporting cycle closed, and why patching a package does not end exposure when access chains through stolen tokens.
A concrete verification checklist. The specific package versions, action tags and exposure windows to check, and what to treat as compromised regardless of whether the tool was invoked.
How the trust boundary should be redrawn. A security tool sits inside the trust boundary of every pipeline it runs in. Very few organizations model it that way, and this is the case study for changing that.
Who this is for
Who should attend
Built for the people who own the pipeline, the alerts it generates, and the intelligence picture behind both.
Security engineering and platform
Teams who own build pipelines and the secrets inside them.
SOC and detection leads
Anyone who needs to know what post-compromise activity looked like in real environments.
CTI analysts
Teams tracking UNC6780 and the broader shift toward developer tooling as an initial access vector.
Presented by
Presented by the team that did the research
The KELA Cyber Intelligence Center tracked TeamPCP from the actor's own channels, through the March waves and the five months that followed.
Senior Analyst, KELA Cyber Intelligence Center
Lead researcher on the TeamPCP investigation
Hear directly from the the person who led the research into TeamPCP.
Good to know
FAQ
When exactly is it, in my timezone?
Monday, August 31, 2026 at 10:00 EST. That is 16:00 CEST for European registrants, and 17:00 in Tel Aviv. The session runs 45 minutes, including Q&A. Your calendar invite arrives immediately after you register.
Two people have been charged. Is this still relevant?
Yes. Charges do not un-poison a package or expire a stolen token. The verification checklist covers the versions, action tags and exposure windows that still need to be checked, whether or not the tool was ever invoked in your pipeline.
Will there be a recording?
Yes. Registered and can't attend? The recording goes to everyone on this list, whether or not you make it live. If the time doesn't work for you, register anyway.
Who should attend?
Security engineering and platform teams who own build pipelines and the secrets inside them, SOC and detection leads who need to know what post-compromise activity looked like in real environments, and CTI analysts tracking UNC6780 and the shift toward developer tooling as an initial access vector.
Is this a product pitch?
No. It is an intelligence briefing on a single campaign: what happened, how it was tracked, and what the evidence supports. Where an assessment is an assessment rather than a confirmed fact, we say so on the slide.
Can I share this with my team?
Please do. Each person should register with their own email so they get their own calendar invite and recording link.
Registration
Monday, August 31, 2026 · 10:00 EST
16:00 CEST for European registrants · 45 minutes, including Q&A
KELA Threat Briefing · TLP:CLEAR
31 Aug · 10:00 EST45 min, incl. Q&A
Save my seat