Cracking TeamPCP: Inside the Downfall of the Infamous Software Supply Chain Syndicate

Share
Cracking TeamPCP: Inside the Downfall of the Infamous Software Supply Chain Syndicate

Executive Overview

In a landmark cross-border operation coordinated by the Australian Federal Police (AFP) in tandem with the Federal Bureau of Investigation (FBI) and Western Australia Police, authorities have arrested two key suspects linked to TeamPCP. This prolific cybercrime and data extortion collective is held responsible for the longest-running and most disruptive software supply chain attack campaign in history.

The sweep netted two Western Australian residents, aged 21 and 23. Australian Broadcasting Corporation (ABC) news later confirmed the identity of the 21-year-old suspect as Ruben Ian Thomson of Cottesloe, alongside 23-year-old Michael Gaebler. Thomson—who operated online under multiple aliases including "Ellis," "BulkDMT," and the TeamPCP spokesperson handle "@pcpcats"—was denied bail following an initial appearance at the Perth Magistrates Court, while Gaebler was remanded in custody ahead of a joint hearing scheduled for September 18.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

TeamPCP’s campaign fundamentally shattered the trust model of open-source software development. Bursting onto the cybercrime scene in late 2025, the syndicate weaponized open-source code repositories via a self-propagating worm named Shai-Hulud. By systematically compromising developer credentials on public platforms like GitHub and npm, TeamPCP injected malicious payloads into foundational software packages, ensnaring thousands of global businesses, major AI infrastructure gateways, and automotive giants.

Despite operating at an industrial scale, the group’s collapse was accelerated by a potent mix of operational security (OpSEC) failures, public bravado, and a trail of digital breadcrumbs left by its leadership—culminating in a series of candid interviews detailing how personal struggles with addiction and isolation paved the way for their undoing.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Detailed Chronology: The Rise and Fall of TeamPCP

The Genesis of Shai-Hulud and Cyclical Exploitation

TeamPCP emerged in late 2025 as a disruptive force, utilizing a self-propagating worm dubbed Shai-Hulud to pierce corporate cloud environments. Writing for Wired, journalist Andy Greenberg dissected the group’s core operational tactic as a cyclical exploitation loop targeting software developers:

  1. Hackers compromise a development network where a commonly used open-source tool is built.
  2. Malicious code is injected into the tool, which is subsequently downloaded and executed on other developers’ machines.
  3. The malware harvests credentials from these secondary machines, granting attackers access to publish malicious updates for downstream tools.
  4. The cycle expands exponentially, compounding the group’s foothold across corporate repositories.

In March 2026, TeamPCP executed a high-profile strike against AI infrastructure by compromising LiteLLM, an open-source gateway connecting users to over 100 large language models. According to security firm CloudSEK, this single operation harvested cloud service keys and sensitive credentials from more than 2,500 organizations, including elite global technology companies. By May, the group claimed credit for compromising at least 3,800 code repositories on Microsoft-owned GitHub after a developer fell victim to a compromised code extension.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The "Cybercats" Collective and Recruitment Contests

Rather than operating as a rigid, hierarchical enterprise, TeamPCP functioned as a peer community of skilled threat actors. This loose affiliation coalesced inside a Matrix chat server dubbed "Cybercats," established earlier this year by security researcher and exploit developer George Prepakis (known online as @kernelstub).

The Cybercats roster served as an operational nerve center for figures associated with multiple distinct cybercrime brands:

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
  • "Boxturtle" (@xpl0itrsturtle): A prominent data breach broker on Breachforums and Darkforums who trafficked stolen data from automotive juggernauts—including BMW, Audi, Honda, Mercedes-Benz, Volvo, and Toyota—as well as data pilfered from Snapchat and SportRadar.
  • "SeesawSec": The mastermind behind Fulcrumsec, an extortion gang linked to attacks on pharmaceutical giant Novo Nordisk, data broker LexisNexis, and Fortune 500 electronic distributor Avnet.
  • "@pcpcasper": Identified by investigators as 23-year-old Michael Gaebler, an active participant in Australian neo-Nazi political organization the National Socialist Network, whose chats and media shared online ultimately tied him to Western Australia.
  • "T" (@pcpcats / Ruben Thomson): The self-described TeamPCP spokesperson and leader.

Seeking to scale their operations further, TeamPCP launched a malicious coding contest in May 2025 following the release of Shai-Hulud 3.0 source code. Offering a $1,000 Monero (XMR) floor prize—dismissed by the actors as a mere "participation trophy"—the contest rewarded participants based on the download volumes of their compromised packages. Security firm Dataminr noted that the competition’s true purpose was talent identification and large-scale acquisition of compromised corporate access.


Supporting Context & Metrics: The OpSEC Anatomy of a Collapse

While TeamPCP possessed elite capabilities in automated supply chain compromise, their operational security was fatally undermined by personal habits, digital footprint reuse, and unmanaged digital habits.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The Trail of Digital Footprints

Security intelligence companies, including Intel 471, Flashpoint, and SpyCloud, meticulously reconstructed the identity of the group’s primary leader through overlapping identifiers:

  • Email & Forum Aliases: Thomson utilized email addresses such as [email protected] and [email protected] across multiple forum iterations (Darkforums, Breachstars, Breachforums, Nulled, and Hackforums) under handles like EllisD25, BulkDMT, Express, and DingoFlour.
  • The South African Connection: Analysis by Flashpoint and Google Threat Intelligence revealed that Thomson frequently operated out of South Africa during early campaigns, referencing local agricultural disputes and political tensions that mirrored his family’s roots in Pietermaritzburg before relocating to Cottesloe, Western Australia.
  • Corporate Paradox: In a glaring irony for a cybercriminal group trading on operational security, Thomson incorporated businesses in Australia under names that mocked his craft, including Secure Computing Solutions, Tensor Industries, and OPSEC Express.
  • The HackerOne Blunder: In June 2025, Thomson registered a profile on vulnerability coordination platform HackerOne under the username Deadcatx3—a handle independently flagged by multiple cybersecurity researchers as a core TeamPCP alias.

Official Statements and Industry Impact

In a joint media release, the Australian Federal Police confirmed the culmination of a months-long joint disruption effort targeting a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." The two men face a combined 14 cybercrime offenses.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

A New Breed of Threat Actor

Industry experts emphasize that TeamPCP represents an evolutionary shift in modern threat intelligence. Charlie Eriksen, a security researcher at Aikido Security, noted that the group defied standard categorization:

"They are not a state actor, not quite organized cybercrime, and not purely ideological. Their motivations seem to mix money, disruption, attention, and ideology."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Eriksen highlighted that the proliferation of Large Language Models (LLMs) has compressed the gap between theoretical research and operational execution. Threat actors can now operate at scale without possessing the institutional discipline or risk-aversion typical of professional criminal organizations or state-sponsored APTs.

"They can be noisy, they can make mistakes," Eriksen observed. "They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Future Outlook and the Legacy of Shai-Hulud

Despite the immense damage inflicted by TeamPCP, security professionals argue that the group inadvertently catalyzed long-overdue systemic reforms in open-source ecosystem security.

For years, software maintainers and security advocates struggled to institute mandatory friction in automated package management. However, the cascading disruption caused by the Shai-Hulud worm forced platform operators to react decisively. In late July, Microsoft-owned GitHub introduced a mandatory three-day "cooldown" period for Dependabot updates, designed to allow security tools and maintainers adequate time to vet newly published package versions before automated deployment. Similar cooldown mechanisms have since been adopted across Python and JavaScript ecosystems.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Eriksen summarized TeamPCP’s paradoxical legacy within the cybersecurity community:

"They managed to wake up Microsoft to the fact that they had become negligent in terms of security. By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

As Ruben Thomson and Michael Gaebler await their next court appearance on September 18, law enforcement agencies maintain that investigations into the broader Cybercats network remain active. The dismantling of TeamPCP serves as both a warning to decentralized cybercrime syndicates and a testament to the resilience of global threat intelligence collaboration.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *