31
 

 Live webinar · KELA Cyber Intelligence CenterTLP:CLEAR

The TeamPCP arrests, from the inside

 

The full story of how KELA supported law enforcement:

Trivy, Checkmarx KICS and LiteLLM fell in five days, the cascade ran for five more months, and in August two men were charged in Perth.

 

Five months after the March waves, the cascade was still producing victims across npm, PyPI and GitHub Actions. On 26 August 2026, the Australian Federal Police charged two men in Perth, working with the FBI and Western Australia Police Force, after receiving information from cyber threat assessment companies. This session walks the full arc, and what it changes about how you model trust in your own pipelines.

Date

Monday
August 31, 2026

Time

10:00 EST
16:00 CEST

Duration

45 min
incl. Q&A

Free · Live

Register here

Register for the live session.

 

Registered and can't attend? The recording goes to everyone on this list.

3security tools poisoned between March 19 and 24, 2026
76/77release tags force-pushed to attacker commits
5 mothe cascade kept producing victims after March
2men charged in Perth on 26 August 2026
1incomplete rotation that made all of it possible

What you'll learn

Five things you'll leave with

Most supply chain attacks find a weak dependency. TeamPCP did something harder to defend against: it compromised the security tools that check the dependencies. Between March 19 and 24, 2026, the group poisoned Trivy, Checkmarx KICS and LiteLLM, and each compromise supplied the credentials for the next.

How the cascade actually worked. Wave by wave, from a service account compromise to 76 of 77 poisoned version tags to malicious releases on PyPI, and why the credential rather than the CVE was the payload.

Why an incomplete rotation was the whole story. A February 2026 breach was patched but not fully rotated. That single gap is what made March possible, and it is the most common version of this failure.

What "still running" looks like in practice. The compromises that landed after the March reporting cycle closed, and why patching a package does not end exposure when access chains through stolen tokens.

A concrete verification checklist. The specific package versions, action tags and exposure windows to check, and what to treat as compromised regardless of whether the tool was invoked.

How the trust boundary should be redrawn. A security tool sits inside the trust boundary of every pipeline it runs in. Very few organizations model it that way, and this is the case study for changing that.

Who this is for

Who should attend

Built for the people who own the pipeline, the alerts it generates, and the intelligence picture behind both.

Security engineering and platform

Teams who own build pipelines and the secrets inside them.

SOC and detection leads

Anyone who needs to know what post-compromise activity looked like in real environments.

CTI analysts

Teams tracking UNC6780 and the broader shift toward developer tooling as an initial access vector.

Presented by

Presented by the team that did the research

The KELA Cyber Intelligence Center tracked TeamPCP from the actor's own channels, through the March waves and the five months that followed.

 

Senior Analyst, KELA Cyber Intelligence Center

Lead researcher on the TeamPCP investigation

Hear directly from the the person who led the research into TeamPCP.

Good to know

FAQ

When exactly is it, in my timezone?

Monday, August 31, 2026 at 10:00 EST. That is 16:00 CEST for European registrants, and 17:00 in Tel Aviv. The session runs 45 minutes, including Q&A. Your calendar invite arrives immediately after you register.

Two people have been charged. Is this still relevant?

Yes. Charges do not un-poison a package or expire a stolen token. The verification checklist covers the versions, action tags and exposure windows that still need to be checked, whether or not the tool was ever invoked in your pipeline.

Will there be a recording?

Yes. Registered and can't attend? The recording goes to everyone on this list, whether or not you make it live. If the time doesn't work for you, register anyway.

Who should attend?

Security engineering and platform teams who own build pipelines and the secrets inside them, SOC and detection leads who need to know what post-compromise activity looked like in real environments, and CTI analysts tracking UNC6780 and the shift toward developer tooling as an initial access vector.

Is this a product pitch?

No. It is an intelligence briefing on a single campaign: what happened, how it was tracked, and what the evidence supports. Where an assessment is an assessment rather than a confirmed fact, we say so on the slide.

Can I share this with my team?

Please do. Each person should register with their own email so they get their own calendar invite and recording link.

Registration

Monday, August 31, 2026 · 10:00 EST

16:00 CEST for European registrants · 45 minutes, including Q&A

Save my seat

KELA Threat Briefing · TLP:CLEAR

Copyright © 2026, KELA · KELA Cyber Intelligence Center

31 Aug · 10:00 EST45 min, incl. Q&A

Save my seat