In a landmark joint international operation, law enforcement authorities in Australia—including the Australian Federal Police (AFP) and the West Australian Police Force, alongside the United States Federal Bureau of Investigation (FBI)—have dismantled a core segment of TeamPCP. Recognized as one of the most prolific and disruptive cybercrime and data extortion syndicates in recent memory, TeamPCP is credited with orchestrating the longest-running software supply chain attack campaign in the history of the internet.
Following early-morning raids in Western Australia, two local men—identified in subsequent media reports as 21-year-old Ruben Ian Thomson and 23-year-old Michael Gaebler—were taken into custody. The suspects face a combined 14 severe cybercrime offenses stemming from their roles in a sophisticated syndicate that allegedly engineered malicious open-source software, weaponized popular development repositories, and extorted thousands of enterprises worldwide.
The takedown of TeamPCP represents a watershed moment for software supply chain security. Over a blistering nine-month operational window, the loosely affiliated cybercrime collective managed to compromise thousands of corporate environments, target artificial intelligence (AI) infrastructure gateways, and systematically humiliate tech giants like Microsoft into fast-tracking critical security upgrades. However, the group’s downfall was ultimately sealed by a combination of high-profile operational security (opsec) failures, persistent digital footprint tracing by cyber intelligence firms, and an investigative deep-dive that exposed the human elements—ranging from struggles with substance abuse to reckless online aliases—behind the code.
Detailed Chronology: The Reign of the Cybercats
The Genesis of a Supply Chain Threat
TeamPCP burst onto the international cybercrime landscape in late 2025, rapidly distinguishing themselves from conventional ransomware gangs by exploiting the trust models underpinning modern software development. Rather than executing standard perimeter breaches or deploying typical credential-stuffing attacks, the syndicate specialized in injecting malicious payloads directly into open-source software repositories maintained by GitHub and NPM.
At the heart of their strategy was Shai-Hulud, a self-propagating worm designed to infiltrate corporate cloud architectures. The worm operated through a compounding cycle of exploitation:
Initial Compromise: Hackers gained administrative or developer access to networks where popular open-source tools were actively built, often via stolen or phished credentials.
Payload Injection: Malicious code was embedded into the targeted utility.
Lateral Infection: When other software developers downloaded and utilized the compromised tool on their local machines—frequently developers crafting other critical coding libraries—the malware silently executed.
Credential Harvesting: The infection harvested credentials and session tokens, allowing TeamPCP to propagate further down the software supply chain and scale their network breaches exponentially.
By May, the group claimed credit for compromising at least 3,800 code repositories on GitHub after a developer innocently installed a malicious code extension seeded by the syndicate.
Targeting the AI Infrastructure
In March, TeamPCP executed what security analysts consider their most audacious operational strike: a supply chain assault targeting LiteLLM, an open-source AI gateway linking users to more than 100 different large language models (LLMs). According to an extensive forensic analysis conducted by cloud security firm CloudSEK, this single vector harvested cloud service keys, proprietary API secrets, and sensitive authentication parameters from more than 2,500 organizations, including a vast cross-section of the world’s leading technology firms.
The "Cybercats" Matrix and Collaborative Extortion
Security researchers emphasize that TeamPCP operated less as a rigid corporate hierarchy and more as a decentralized "peer community" of skilled threat actors. This confederation coalesced on a Matrix chat server dubbed "Cybercats," established by an accomplished exploit developer and security researcher who goes by the online handle @kernelstub (publicly identified as George Prepakis).
Within the Cybercats ecosystem, various prominent cybercriminal handles collaborated, shared stolen data sets, and coordinated multi-vector extortion campaigns:
Boxturtle (@xpl0itrs): A noted data breach broker linked to major ransom operations targeting automobile giants including BMW Group, Audi, Honda, Mercedes-Benz, Volvo, and Toyota.
SeesawSec: The alias tied to Fulcrumsec, a group claiming responsibility for high-profile data extortion attacks against pharmaceutical giant Novo Nordisk, data broker LexisNexis, and Fortune 500 electronics distributor Avnet.
@pcpcasper (Michael Gaebler): An active participant whose digital footprint heavily linked him to the Australian neo-Nazi political organization, the National Socialist Network, and who was ultimately arrested alongside Thomson.
Crowdsourcing Cybercrime: The Shai-Hulud 3.0 Contest
Demonstrating an unorthodox approach to recruitment and operations, TeamPCP published the source code for the third iteration of Shai-Hulud online in May. Shortly thereafter, they launched a global contest offering $1,000 in Monero (XMR) cryptocurrency to whichever participant could execute the largest supply chain operation using the worm.
Participants were scored based on weekly and monthly download counts of their compromised packages, directly incentivizing attacks against the most widely utilized software libraries. Cybersecurity firm Dataminr noted that the $1,000 prize served merely as a "recruitment floor"—with TeamPCP leadership openly stating that participants who harvested high-value corporate access would be compensated with significantly higher payouts.
Supporting Context & Metrics: Unraveling the Opsec Failures
The identification and subsequent arrest of Ruben Thomson—known across dark web forums by aliases such as EllisD25, BulkDMT, Express, and Deadcatx3—illustrate a classic case of operational security breakdown. Despite deploying sophisticated malware, the group’s core leader repeatedly tripped over basic digital hygiene rules.
The Paper Trail of Aliases and Infrastructure
Investigators from threat intelligence firms including Intel 471, Flashpoint, and SpyCloud connected a dense web of identities:
The Email Link: Threat intelligence tracking revealed that the email address [email protected]—used by the forum user "Express" to register on Breachforums—was historically tied to an account named "ChristmasSnow" on Raidforums. Passive DNS records and Internet Service Provider (ISP) logs traced these activities directly to residential IP addresses in Perth, Western Australia.
Family Infrastructure: Passive DNS records maintained by DomainTools mapped a private Perth family file server (211.27.196.111) operated by the Thomson family, leading investigators to Ruben Thomson’s relatives, including his dentist father Ian.
Corporate Irony: In a striking display of poor opsec, Ruben Thomson incorporated several legitimate Australian businesses—including Secure Computing Solutions, Tensor Industries, and OPSEC Express—directly utilizing variants of his own cybercrime monikers.
The HackerOne Blunder: In June 2025, an individual registering under the legal name Ruben Thomson opened an account on the bug-bounty platform HackerOne using the username Deadcatx3—an alias already heavily flagged by multiple security firms as a primary identifier for TeamPCP leadership.
Official Statements and Legal Proceedings
In an official media release, the Australian Federal Police confirmed that two Western Australian men, aged 21 and 23, were apprehended following a synchronized operation executed in coordination with the FBI and the West Australian Police Force.
"This operation targeted a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses," the AFP stated.
According to updates provided by Australian broadcasting network ABC News, Ruben Ian Thomson of Cottesloe and Michael Gaebler appeared before the Perth Magistrates Court. Thomson was formally denied bail by the presiding magistrate, while legal counsel for Gaebler did not formally request bail. Both suspects remain remanded in custody ahead of their next scheduled court appearance on September 18.
Future Outlook: The Legacy of TeamPCP on Software Supply Chains
While the apprehension of Thomson and Gaebler deals a severe blow to the operational capabilities of TeamPCP, the broader cybersecurity community is left analyzing the group’s profound, lasting impact on digital infrastructure.
The Changing Face of Threat Actors
Security researchers point out that TeamPCP embodies a disruptive new breed of cybercriminal: neither state-sponsored actors nor financially motivated ransomware cartels, they operated out of a volatile mix of technical curiosity, anti-social ideology, and digital adrenaline.
Charlie Eriksen, a security researcher at Aikido Security, highlighted how generative artificial intelligence and large language models have compressed the learning curve for amateur hackers.
"You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets," Eriksen noted. "LLMs have compressed that gap significantly."
This capability compression allows individuals with minimal formal software engineering backgrounds to orchestrate global-scale disruptions, though frequently accompanied by sloppy operational security and rapid burnout.
The Silver Lining: Forced Industry Safeguards
Paradoxically, security analysts have credited TeamPCP’s aggressive campaign with accelerating much-needed structural defenses across the open-source community.
In direct response to the Shai-Hulud worm and poisoned package distributions, Microsoft and GitHub introduced a mandatory three-day "cooldown" mechanism for Dependabot in late July. Designed to pause automated dependency updates, these cooldown periods grant security teams and package maintainers vital windows to vet newly published releases before they propagate into enterprise systems. Parallel ecosystems across Python and JavaScript have similarly rushed to adopt cooldown protocols.
Ultimately, TeamPCP’s legacy will be defined not merely by the breadth of their intrusions—affecting thousands of companies from AI gateways to automotive conglomerates—but by how violently they shook the software development ecosystem awake. By exposing the extreme fragility of trusting public code repositories, TeamPCP forced platforms to adopt baseline security architectures that developers and security experts had demanded for over a decade.