Webinar

The TeamPCP arrests, from the inside

Share:

KELA on-demand webinar banner: The TeamPCP arrests, from the inside, with Ben Kapon and Jimmy
play

Please fill out the form to watch

Five months after the March waves, the cascade was still producing victims across npm, PyPI and GitHub Actions. On 26 August 2026, the Australian Federal Police charged two men in Perth, working with the FBI and Western Australia Police Force, after receiving information from cyber threat assessment companies. This session walks the full arc, and what it changes about how you model trust in your own pipelines.

Key Topics:

  • How the cascade actually worked. Wave by wave, from a service account compromise to 76 of 77 poisoned version tags to malicious releases on PyPI, and why the credential rather than the CVE was the payload.
  • Why an incomplete rotation was the whole story. A February 2026 breach was patched but not fully rotated. That single gap is what made March possible, and it is the most common version of this failure.
  • What “still running” looks like in practice. The compromises that landed after the March reporting cycle closed, and why patching a package does not end exposure when access chains through stolen tokens.
  • A concrete verification checklist. The specific package versions, action tags and exposure windows to check, and what to treat as compromised regardless of whether the tool was invoked.
  • How the trust boundary should be redrawn. A security tool sits inside the trust boundary of every pipeline it runs in. Very few organizations model it that way, and this is the case study for changing that.

Speakers:

Ben Kapon

Ben Kapon

VP Marketing

Jimmy

Jimmy

Senior Analyst @KELA

Watch now!

Related Resources

KELA report cover: TeamPCP Threat Actor Profile

TeamPCP Threat Actor Profile

KELA press release banner: "Breaking: KELA research leads to alleged TeamPCP members arrested," with police escorting a person in custody

KELA research leads to alleged TeamPCP Members Arrested

KELA report cover: 2026 AI Threat Landscape Report

2026 AI Threat Landscape Report