Executive Overview
In a landmark coordinated international law enforcement sweep, Australian authorities—in close collaboration with the Federal Bureau of Investigation (FBI) and Western Australia Police—have arrested two men suspected of being central figures in TeamPCP, a prolific and disruptive cybercrime syndicate. The 21- and 23-year-old suspects, apprehended in Western Australia, face a combined 14 charges relating to a sprawling campaign of malicious open-source software injection and global data extortion.
TeamPCP rose to notoriety in late 2025 as the orchestrator of what security experts have dubbed the longest-running software supply chain attack spree in history. Utilizing a self-propagating worm known as Shai-Hulud, the decentralized collective systematically compromised corporate environments, infiltrated artificial intelligence infrastructure, and breached thousands of repositories across major platforms like GitHub and NPM.
This deep-dive investigation examines the architecture of TeamPCP’s campaign, the messy digital breadcrumbs that led to the unmasking of the group’s principal leader—Ruben Thomson, operating under aliases such as "Ellis," "BulkDMT," and "Deadcatx3"—and the wider implications of a new breed of threat actors accelerated by artificial intelligence and plagued by volatile operational security (OPSEC) failures.

Detailed Chronology: The Rise and Fall of TeamPCP
The Campaign of the Shai-Hulud Worm
TeamPCP blasted onto the global cybercrime radar in late 2025, deploying an aggressive and cyclical exploitation strategy designed to weaponize trust within the software development community. Rather than breaching corporate firewalls through traditional perimeter attacks, TeamPCP targeted the foundational supply chain upon which modern software is built.
According to analyses by major cybersecurity firms and journalism from outlets like Wired, the group’s core mechanism relied on credential harvesting through phished or stolen developer accounts on public code repositories. Once inside, TeamPCP embedded malicious payloads into widely used open-source libraries. When developers pulled these tools into their local machines—often tools intended to build other developer utilities—the self-propagating Shai-Hulud worm executed silently, harvesting fresh credentials and propagating the infection exponentially.
By March 2026, the syndicate escalated its operations by striking critical AI infrastructure. TeamPCP compromised the source code for LiteLLM, an open-source AI gateway linking users to more than 100 large language models. Security firm CloudSEK later revealed that this single breach harvested cloud service keys and sensitive secrets from over 2,500 organizations, including top-tier global technology companies. By May 2026, the group claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned GitHub after a single developer installed a compromised extension.

Decentralized Crime: Meet the "Cybercats"
Cybersecurity analysts emphasize that TeamPCP was never a traditional hierarchical criminal gang with a single commander. Instead, it operated as a loose federation of skilled threat actors from multiple underground milieus. This peer community coalesced around a Matrix chat server dubbed Cybercats, established earlier in the year by security researcher and exploit developer George Prepakis (known online as @kernelstub).
Within the Cybercats server, prominent figures coordinated extortion operations, shared victim lists, and taunted targets publicly via X (formerly Twitter) long before breaches hit the news cycle. Key nodes included:
- Boxturtle (
@xpl0itrsturtle): Linked to data breach broker profiles on Breachforums and Darkforums, hawking stolen corporate data from automotive giants such as BMW, Audi, Honda, Mercedes-Benz, Volvo, and Toyota. - SeesawSec: The alias behind Fulcrumsec, an extortion group claiming responsibility for attacks against pharmaceutical titan Novo Nordisk, data broker LexisNexis, and Fortune 500 distributor Avnet.
@pcpcasper(identified as 23-year-old Michael Gaebler): An active participant who mixed cybercrime chatter with radical extremist ideologies, whose digital footprints ultimately tied him to Western Australia and subsequent arrest.
The Unraveling of "Ellis" (Ruben Thomson)
The syndicate’s undoing was catalyzed by a combination of aggressive open-source intelligence (OSINT) tracking by security researchers—notably Brian Krebs—and staggering operational security (OPSEC) failures by TeamPCP’s primary leader, Ruben Thomson.

Thomson operated under a shifting constellation of handles: EllisD25/LSD on Darkforums, BulkDMT on Breachstars, Express on Breachforums, and Persy_PCP on Telegram. Through these accounts, he managed a virtual private server hosting service called "DMT Host" and discussed his personal struggles with methamphetamine addiction, a nomadic lifestyle spanning South Africa and Australia, and his alienation from traditional employment.
Despite adopting these aliases, Thomson repeatedly tripped over his own digital infrastructure:
- Email Overlaps: Registration emails such as
[email protected]and[email protected]linked forum profiles directly back to historic accounts in Perth, Australia, including a 2022 Raidforums account named "ChristmasSnow." - Passive DNS and Family Footprints: Passive DNS records and public business registries in Western Australia tied IP addresses used by Thomson to family web servers managed by his father, Ian Thomson, a Cottesloe dentist originally from South Africa.
- Corporate Missteps: In an ironic failure of "OPSEC" (operational security), Thomson registered Australian business entities under names like Secure Computing Solutions, Tensor Industries, and OPSEC Express.
- The Bug Bounty Blunder: In June 2025, Thomson registered an account on the vulnerability coordination platform HackerOne using the username Deadcatx3—an exact handle independently flagged by multiple cybersecurity firms as a core alias used by TeamPCP.
Supporting Context & Metrics: The Human and Technical Equations
Interviews with the Insider
In July 2026, shortly after uncovering Thomson’s real-world identity, security journalist Brian Krebs conducted an extensive Signal interview with the TeamPCP leader, who spoke candidly under the moniker "Ellis."

Ellis claimed he stepped back from active cybercrime for TeamPCP in March 2026, right before the LiteLLM supply chain attacks. Describing his entry into the underworld, Ellis noted that he was two months sober from narcotics when he reconnected with old malware development peers who needed help monetizing GitHub credentials.
"Blackhatting is fun," Ellis remarked during the interview. "There are actual rewards and incentives to learn, and you grow with your team. Without qualifications, no employer will even take the time to hear you out."
Ellis estimated he earned roughly $20,000 across his tenure with TeamPCP, maintaining that financial enrichment was secondary to the intellectual stimulation and camaraderie. Throughout his chats with fellow Cybercats members, however, his battles with substance abuse remained acute. Conversations frequently detailed plans to use dissociative anesthetics like ketamine, synthetic DMT, and 2C-B, culminating in erratic absences followed by multi-day recovery crashes.

The AI Knowledge Gap and New Threat Models
Security researcher Charlie Eriksen of Aikido Security points out that TeamPCP represents a dangerous evolutionary step in modern threat actors. Operating outside the bounds of nation-state espionage or financially driven ransomware cartels, groups like TeamPCP are motivated by a volatile mixture of curiosity, disruption, ideological grievance, and ego.
Furthermore, Eriksen highlights how large language models (LLMs) have drastically compressed the barrier to entry for complex cyber operations:
- Traditional Path: Threat actors had to spend years studying research, writing custom code, debugging payloads, building robust C2 infrastructure, and testing across ecosystems.
- AI-Accelerated Path: LLMs allow semi-skilled developers to bridge the technical knowledge gap rapidly, enabling them to execute large-scale, high-impact supply chain operations without mastering the foundational discipline required to maintain clean operational security.
Consequently, while these groups are frequently "noisy," making tactical errors and leaving digital evidence in their wake, their ability to execute widespread damage makes them uniquely volatile and dangerous.

Official Statements and Legal Proceedings
The Australian Federal Police formally announced the arrests in a joint media release detailing the disruption of the global cybercrime syndicate. AFP officers executed search warrants alongside the Western Australia Police Force, apprehending the two men in Perth.
- Ruben Ian Thomson (21, Cottesloe): Denied bail during his initial appearance at the Perth Magistrates Court. Prosecutors charged him with multiple offenses related to unauthorized access, malicious code distribution, and extortion.
- Michael Gaebler (23): Arrested alongside Thomson. Legal counsel for Gaebler did not request bail during the initial hearing.
Both defendants are remanded in custody ahead of their next scheduled court appearance on September 18. The AFP emphasized that the operation relied heavily on international cooperation, notably intelligence-sharing with the FBI and global threat intelligence providers.
Future Outlook: The Legacy of TeamPCP and Industry Hardening
While the dismantling of TeamPCP marks a major victory for international law enforcement, the syndicate’s structural legacy on software development security will resonate for years.

Security analysts argue that TeamPCP’s aggressive abuse of trusted publishing mechanisms ultimately served as a painful but necessary wake-up call for the software industry. In direct response to the Shai-Hulud worm and subsequent supply chain compromises:
- GitHub and Ecosystem Cooldowns: In late July, Microsoft-owned GitHub instituted a mandatory three-day "cooldown" period for Dependabot version updates. This delay gives package maintainers and automated security scanners vital breathing room to flag and intercept poisoned libraries before they cascade into enterprise production environments.
- Ecosystem-Wide Adoption: Similar cooldown mechanisms have been adopted across Python (PyPI) and JavaScript packaging ecosystems, driven by unified industry demands to overhaul trust models.
Ultimately, TeamPCP achieved in a matter of months what security advocates had urged enterprise software platforms to implement for decades. As Charlie Eriksen observed, they forced the tech industry to take supply chain security seriously—even if the price of that lesson was paid in widespread corporate disruption and the ultimate downfall of two young men whose brilliant technical curiosities were swallowed by addiction and unchecked digital hubris.
