Executive Overview
In a joint international sweep that marks a watershed moment for software supply chain security, law enforcement authorities in Australia have arrested two men allegedly tied to TeamPCP, a prolific and disruptive cybercrime syndicate. The operation—conducted by the Australian Federal Police (AFP) alongside the Federal Bureau of Investigation (FBI) and the Western Australia Police Force (WAPF)—culminated in the apprehension of two Western Australian residents, aged 21 and 23.
The suspects are accused of orchestrating a sophisticated global cybercrime campaign that leveraged malicious open-source software, self-propagating worms, and targeted credential theft to compromise thousands of businesses worldwide.
TeamPCP first burst onto the threat landscape in late 2025, quickly earning notoriety as the operator of the longest-running and most damaging software supply chain attack spree in history. Rather than relying on traditional perimeter breaches, the group targeted the bedrock of modern software development: open-source code repositories, AI infrastructure gateways, and developer toolchains.

Through a combination of digital forensics, persistent investigative journalism, and a series of glaring operational security (OPSEC) failures by the syndicate’s leadership, the true identities of the group’s core architects were unmasked. The arrests in Perth underscore a broader paradigm shift in modern cybercrime: a new breed of threat actors who operate at massive, chaotic scale, driven by a volatile mix of financial opportunism, digital nihilism, and ideological alignment, yet ultimately undone by their own human frailties and digital footprints.
Detailed Chronology: The Rise and Fall of a Supply Chain Menace
The Genesis of the "Shai-Hulud" Worm and Cyclical Exploitation
TeamPCP’s operational model represented a terrifying evolution in software supply chain compromise. The group’s primary vector of destruction was a self-propagating worm dubbed Shai-Hulud.
Security analysts describe TeamPCP’s core strategy as a cyclical exploitation loop targeting software developers. The attack chain typically followed a structured progression:

- Initial Access: The hackers compromised corporate cloud environments and developer workstations after harvesting phished or stolen credentials from public code repositories such as GitHub or NPM.
- Planting the Payload: Malicious code was embedded directly into open-source software tools commonly utilized by developers.
- Lateral Propagation: When unsuspecting developers downloaded and utilized these compromised tools on their local machines, the malware surreptitiously harvested additional credentials and cloud service keys.
- Recursive Compromise: Armed with fresh credentials for other developer toolchains, TeamPCP published malicious updates to secondary repositories, exponentially expanding their collection of breached networks.
This strategy allowed the syndicate to bypass traditional defenses by weaponizing the inherent trust model of open-source ecosystems. In March, TeamPCP executed a high-profile attack targeting artificial intelligence infrastructure by compromising LiteLLM, an open-source AI gateway linking users to more than 100 large language models. Analysis by security firm CloudSEK revealed that this single breach harvested cloud service keys and sensitive secrets from over 2,500 organizations, including major global technology companies. By May, the group claimed responsibility for compromising at least 3,800 code repositories on GitHub after a developer installed a malicious code extension.
Gamified Recruitment and the "Cybercats" Community
Rather than functioning as a traditional, tightly compartmentalized cybercrime cartel, security experts from the Google Threat Intelligence Group characterized TeamPCP as a loose federation of peer threat actors from multiple disparate gangs collaborating toward shared objectives. Austin Larsen, a principal threat analyst at Google, noted that the group was "a peer community of individually-skilled actors, with one clear center of gravity."
That center of gravity coalesced around a Matrix chat server dubbed "Cybercats," created by an accomplished security researcher and self-described exploit developer operating under the handle @kernelstub (identified as George Prepakis). For months, members of TeamPCP and allied cybercrime groups used this server for daily communication, operational planning, and public taunting of victims.

The Cybercats roster included several notable criminal personas:
- Boxturtle (
@xpl0itrsturtle): A prominent data breach broker active on Breachforums and Darkforums, linked to massive data thefts from global automotive manufacturers—including BMW, Audi, Honda, Mercedes-Benz, Volvo, and Toyota—as well as Snapchat and SportRadar. - SeesawSec: The alias associated with Fulcrumsec, an extortion gang that claimed credit for high-profile cyberattacks against pharmaceutical giant Novo Nordisk, data broker LexisNexis, and Fortune 500 electronic component distributor Avnet.
@pcpcasper: A vocal Telegram participant tied to the Australian neo-Nazi political organization, the National Socialist Network. Geolocational clues shared in chats eventually placed this user in Western Australia.
In May, TeamPCP launched an aggressive recruitment drive. Following the release of the source code for the third iteration of the Shai-Hulud worm, the syndicate announced a contest offering a $1,000 Monero (XMR) floor prize to the participant who could execute the largest supply chain operation using the worm’s code. Designed as a talent identification mechanism, the contest scored participants based on the weekly and monthly download counts of their compromised packages, directly incentivizing attacks on the most widely utilized code libraries.
The Unraveling: OPSEC Failures and Investigative Breakthroughs
Despite executing sophisticated technical intrusions, TeamPCP’s leadership suffered from catastrophic operational security failures. The primary leader of TeamPCP—operating under various aliases including EllisD25/LSD, BulkDMT, Express, and Persy_PCP—left a digital paper trail that spanned years across multiple forums, messaging apps, and public registries.

Investigative work by security journalist Brian Krebs, combined with intelligence from firms such as Intel 471, Flashpoint, SpyCloud, and DomainTools, traced the digital breadcrumbs back to a family in Perth, Australia.
- The Email Thread: The email address
[email protected], used to register cybercrime forum accounts, was historically linked to an account named ChristmasSnow on Raidforums in 2022, which predominantly accessed platforms via Internet Service Providers in Perth. - Passive DNS and Domain Registrations: Passive DNS records revealed a private file server hosted at a residential IP address in Perth used by a family with the surname Thomson. Open-source intelligence and public registries tied these infrastructure footprints to Ian Thomson, a local dentist, and his sons.
- The Alias Connection: While one brother maintained a clean profile, the other—Ruben Thomson—maintained an extensive presence on illicit hacking forums dating back to 2018 under handles such as
[email protected]and[email protected]. Ruben used the online persona Ellis and openly described himself as a full-stack web developer and PHP programmer. - The Ultimate OPSEC Blunder: In June 2025, Ruben Thomson registered an account on HackerOne—a legitimate bug bounty platform—using the username Deadcatx3. Multiple cybersecurity firms had previously cataloged
Deadcatx3as a core alias utilized by TeamPCP leadership. Furthermore, Ruben incorporated local Australian businesses under names that brazenly mirrored his cybercrime handles, including OPSEC Express.
Supporting Context & Metrics: The Scale of the Damage
The operational footprint of TeamPCP shattered long-held assumptions regarding the resilience of software supply-chain security. Key metrics highlighting the breadth of their campaign include:
- Duration: More than nine months of continuous, highly active software supply chain intrusions, making it the longest-running campaign of its kind recorded to date.
- Target Reach: Over 3,800 GitHub code repositories compromised in a single wave; LiteLLM intrusion harvesting cloud service keys from more than 2,500 corporate organizations globally.
- Ecosystem Impact: Direct targeting of JavaScript (NPM), Python, and AI integration packages, forcing major repositories to re-evaluate their publishing trust models.
- Financial Yield: Despite the global panic and enterprise remediation costs totaling millions of dollars, internal communications from the primary suspect indicated a personal payout of roughly $20,000, illustrating a stark disparity between enterprise damage and criminal financial return.
Official Statements and Legal Proceedings
In a formal media release issued jointly by federal and state law enforcement, the Australian Federal Police confirmed the execution of search warrants and the subsequent arrest of the two Western Australian men, aged 21 and 23.

"This operation targeted a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses," the AFP stated.
The suspects face a combined total of 14 cybercrime offenses. According to follow-up reports from Australian broadcaster ABC News, Ruben Ian Thomson (21, of Cottesloe) was denied bail during his initial appearance at the Perth Magistrates Court. The second suspect, 23-year-old Michael Gaebler (identified by investigators as the user behind @pcpcasper), appeared alongside Thomson. Both men were remanded in custody, with their next court appearance scheduled for September 18.
Future Outlook: Industry Implications and the "Cooldown" Era
Security researchers emphasize that TeamPCP represents the vanguard of a disturbing new class of cyber adversary. Charlie Eriksen, a security researcher at Aikido Security, noted that TeamPCP blurred the traditional boundaries of threat intelligence:

"They are not a state actor, not quite organized cybercrime, and not purely ideological. Their motivations seem to mix money, disruption, attention, and ideology."
Eriksen pointed out that the proliferation of Large Language Models (LLMs) and artificial intelligence has significantly compressed the knowledge gap in cybersecurity. Adversaries no longer require decades of foundational systems engineering expertise to adapt research code, troubleshoot exploits, and construct automated infrastructure at scale. This democratization of capability produces threat actors who are technically proficient enough to inflict catastrophic enterprise damage, yet lack the operational discipline—or foresight—of traditional criminal syndicates.
The Silver Lining: Forced Reform at GitHub and Beyond
Ironically, security experts have argued that TeamPCP’s aggressive campaign may ultimately yield a more secure global software ecosystem. Dubbing the Shai-Hulud worm "the best thing to happen to supply chain security," Eriksen and other analysts credit the syndicate’s disruptive attacks with shaming major technology platforms into enacting long-overdue protective safeguards.

In direct response to TeamPCP’s supply chain poisoning exploits, GitHub introduced a mandatory three-day "cooldown" period for Dependabot version updates in late July. This mechanism introduces a deliberate temporal buffer between the moment a software package is published and when automated tools fetch it, providing security researchers and package maintainers critical window space to identify, report, and purge malicious dependencies before they integrate into corporate production environments. Similar cooldown frameworks have since been adopted across various Python and JavaScript package ecosystems.
While the arrests of Ruben Thomson and Michael Gaebler effectively decapitate TeamPCP’s core leadership, the structural vulnerabilities exposed by their campaign remain a stark warning to the global tech sector. As open-source dependencies continue to power the digital economy, the legacy of TeamPCP will serve as a permanent reminder that trust cannot be assumed, and that operational security applies equally to the defenders and the defenders-turned-adversaries.
