Unmasking TeamPCP: Inside the Fall of the World’s Most Destructive Software Supply Chain Syndicate

Executive Overview

In what law enforcement agencies are calling one of the most critical cybercrime disruptions of the decade, the Australian Federal Police (AFP), working in tandem with the Federal Bureau of Investigation (FBI) and Western Australia Police Force (WAPF), has dismantled the core operational ring of TeamPCP. Responsible for the longest-running and most destructive software supply chain attack spree in history, the cybercrime syndicate targeted major cloud ecosystems, compromised thousands of enterprise code repositories, and extorted global corporations.

The operation culminated in the arrest of two primary suspects in Western Australia: 21-year-old Ruben Ian Thomson of Cottesloe and 23-year-old Michael Gaebler. Facing a combined 14 federal cybercrime charges, both men were denied bail at their initial appearance in Perth Magistrates Court and remain in custody.

TeamPCP’s campaign utilized a self-propagating malicious worm dubbed Shai-Hulud, which hijacked developer credentials across public repositories like GitHub and NPM to poison open-source software libraries. From compromising critical AI infrastructure to breaching auto manufacturing giants and Fortune 500 distributors, the syndicate exposed deep structural vulnerabilities in the global technology supply chain.

An extensive open-source intelligence (OSINT) investigation, combined with direct interviews conducted prior to the arrests, reveals a complex picture of the group’s operations. Driven by a chaotic blend of drug abuse, nihilistic online subcultures, and accessible artificial intelligence tools, TeamPCP achieved massive scale despite catastrophic operational security failures.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Detailed Chronology of the Supply Chain Spree

+-----------------------------------------------------------------------------------+
|                            TEAMPCP OPERATIONAL TIMELINE                           |
+-----------------------------------------------------------------------------------+
| Late 2025       | Syndicate emerges; begins weaponizing open-source libraries     |
|                 | via stolen GitHub and NPM developer credentials.                 |
|-----------------|-----------------------------------------------------------------|
| March 2026      | Executes supply chain breach on LiteLLM AI gateway; steals cloud |
|                 | service keys from 2,500+ enterprises.                           |
|-----------------|-----------------------------------------------------------------|
| May 2026        | Launches Shai-Hulud 3.0 along with a $1,000 XMR "hacking contest" |
|                 | to crowdsource package poisoning.                               |
|-----------------|-----------------------------------------------------------------|
| May 2026        | Compromises 3,800+ GitHub code repositories via a malicious       |
|                 | developer extension.                                            |
|-----------------|-----------------------------------------------------------------|
| Mid-2026        | Coordinates extortion campaigns with "Cybercats" network against |
|                 | automotive, pharmaceutical, and tech sectors.                   |
|-----------------|-----------------------------------------------------------------|
| August 2026     | AFP/FBI joint operation arrests Ruben Thomson and Michael      |
|                 | Gaebler in Perth; both held without bail.                       |
+-----------------------------------------------------------------------------------+

The Initial Breakthrough (Late 2025)

TeamPCP surfaced in late 2025, initially operating quietly within dark web forums and underground Telegram channels. The syndicate developed a methodology for automating credential theft among software engineers. By targeting individual developers through phishing and token-harvesting malware, the actors gained write access to widely used open-source software repositories. Once inside, they injected backdoors into package updates, creating an automated pipeline for downstream compromises.

The LiteLLM AI Gateway Compromise (March 2026)

In March 2026, TeamPCP executed its most far-reaching attack against artificial intelligence development infrastructure. The group breached LiteLLM, an open-source AI gateway used to route requests across more than 100 large language models (LLMs).

A forensic analysis conducted by cybersecurity firm CloudSEK revealed that TeamPCP weaponized the LiteLLM codebase to silently harvest cloud service provider keys, API tokens, and corporate credentials. The attack impacted:

  • Over 2,500 organizations, including top-tier Silicon Valley firms.
  • More than 434,000 Continuous Integration/Continuous Deployment (CI/CD) pipelines, granting TeamPCP persistent access to corporate cloud environments.

Shai-Hulud 3.0 and Crowdsourced Exploitation (May 2026)

By May 2026, TeamPCP escalated its operations by deploying the third iteration of its signature worm, Shai-Hulud. To maximize disruption, the group launched a crowdsourced supply chain hacking contest. TeamPCP published the worm’s source code online and offered a floor prize of $1,000 in Monero (XMR) to external hackers who could execute the largest supply chain infection.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Competitors were scored based on the weekly and monthly download counts of the code packages they managed to compromise. Intelligence firm Dataminr noted that the tournament served as an access acquisition vehicle, with TeamPCP offering to buy high-value corporate footholds harvested by third-party participants.

Mass Compromise of GitHub Infrastructure (May 2026)

Later that month, a developer at Microsoft-owned GitHub unknowingly installed a browser extension infected with TeamPCP malware. The resulting credential leak allowed TeamPCP to compromise at least 3,800 code repositories hosted on GitHub. The incident forced tech companies worldwide to rotate security keys and inspect thousands of internal codebases for backdoors.


Technical Context and Metrics

The Mechanism of the Shai-Hulud Worm

The core engine behind TeamPCP’s campaign was the Shai-Hulud worm. Writing for Wired, cybersecurity journalist Andy Greenberg detailed the self-sustaining nature of the attack cycle:

"The hackers gain access to a network where an open source tool commonly used by coders is being developed. The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
                    [ Stolen Developer Credentials ]
                                  │
                                  ▼
                    [ Poisoned Open-Source Package ]
                                  │
                                  ▼
         ┌─────────────────────────────────────────────────┐
         │ Automated Distribution via NPM/GitHub Updates   │
         └─────────────────────────────────────────────────┘
                                  │
                                  ▼
            [ Downstream Developer Machine Infected ]
                                  │
                                  ▼
          [ Harvest New Cloud Keys & Repository Tokens ]
                                  │
                                  └─────────► (Cycle Repeats at Scale)

The "Cybercats" Extortion Network

TeamPCP did not operate in isolation. Security researchers identified the syndicate as a core node within a broader cybercrime coalition known as Cybercats, hosted on an encrypted Matrix chat server established by George Prepakis (operating online as @kernelstub).

The Cybercats ecosystem united distinct threat actors who shared infrastructure, access, and victim lists:

  • xpl0itrs / Boxturtle: Operated by an alias linked to @xpl0itrsturtle, this actor specialized in selling stolen corporate data on Breachforums and Darkforums. Exfiltrated data included proprietary networks and customer databases from automotive giants including BMW Group, Audi, Honda, Mercedes-Benz, Volvo, and Toyota, alongside additional breaches at Snapchat and SportRadar.
  • Fulcrumsec / SeesawSec: Executed extortion operations targeting global enterprises, claiming responsibility for data thefts at pharmaceutical firm Novo Nordisk, data broker LexisNexis, and electronic component distributor Avnet.
  • @pcpcasper (Michael Gaebler): Served as an active member of both Cybercats and TeamPCP. Forensic digital footprinting linked Gaebler’s online personas to videos posted within Telegram channels associated with the National Socialist Network, an Australian neo-Nazi political movement.
+-------------------------------------------------------------------------------------+
|                              CYBERCATS NETWORK ENTITIES                             |
+-------------------+----------------------------+------------------------------------+
| Actor / Alias     | Primary Platform Handles   | Notable Targets & Activities       |
+-------------------+----------------------------+------------------------------------+
| @kernelstub       | Cybercats Admin            | Infrastructure host, exploit dev   |
| Boxturtle         | xpl0itrs, @xpl0itrsturtle2  | BMW, Audi, Honda, Toyota, Snapchat |
| SeesawSec         | Fulcrumsec                 | Novo Nordisk, LexisNexis, Avnet    |
| @pcpcasper        | Michael Gaebler            | Supply chain operations, NSN org   |
| Ellis / T         | Ruben Thomson / @pcpcats   | TeamPCP leader, Shai-Hulud author  |
+-------------------+----------------------------+------------------------------------+

Unmasking the Leader: OSINT Trajectory

Despite TeamPCP’s technical success, the group’s leader left a trail of digital evidence spanning nearly a decade. Known variously as Ellis, EllisD25, BulkDMT, Express, DMT Host, Persy_PCP, and @pcpcats, the threat actor behind the handle was identified as 21-year-old Ruben Ian Thomson.

[Forum Handle: Express] ──► [Email: [email protected]] ──► [Raidforums: ChristmasSnow]
                                                                          │
                                                                          ▼
[Home File Server IP] ◄── [Domain: thomson.org.au] ◄── [Perth ISP Address: 211.27.196.111]
         │
         ├─► Synology Server (ithomson.direct.quickconnect.to)
         └─► QNAP NAS Device (joshuawthomson39.myqnapcloud.com)

Digital Footprints and IP Cross-Referencing

  1. Breach Forum Registrations: Intel 471 and SpyCloud tracked the email address [email protected], used by "Express" on Breachforums, back to a 2022 account named "ChristmasSnow" on Raidforums.
  2. Infrastructure Links: ISP connection records mapped the account’s traffic to a static IP address in Perth, Australia (211.27.196.111). Passive DNS history maintained by DomainTools revealed that this address hosted local network storage devices for the Thomson family, including ithomson.direct.quickconnect.to and joshuawthomson39.myqnapcloud.com.
  3. Cross-Account Re-use: Investigators linked secondary accounts ([email protected] and [email protected]) across Altenen, Hackforums, Nulled, and Upwork. The user registered an Upwork profile under the name Ruben Thomson, offering Linux server configuration and Python scripting services.
  4. The Ultimate OPSEC Failure: In 2024 and 2025, Thomson officially registered several corporate entities with the Australian Securities and Investments Commission (ASIC), including Secure Computing Solutions, Tensor Industries, and OPSEC Express—incorporating his dark web handle directly into official government business filings. Furthermore, in June 2025, Thomson created a HackerOne bug bounty account under his real name while choosing the username Deadcatx3, an alias publicly identified by threat intelligence analysts as a core TeamPCP signature.
+------------------------------------------------------------------------------------+
|                         RUBEN THOMSON OSINT CORRELATION                            |
+-----------------------+------------------------------------------------------------+
| Pivot Point           | Identified Entity / Evidence                               |
+-----------------------+------------------------------------------------------------+
| Email Addresses       | [email protected], [email protected]             |
| Dark Web Handles      | EllisD25, BulkDMT, Express, DMT Host, Persy_PCP, Deadcatx3 |
| Physical Location     | Cottesloe, Western Australia (Family roots: South Africa)  |
| Network Storage       | Synology / QNAP endpoints on home IP (211.27.196.111)      |
| Business Filings      | Tensor Industries, OPSEC Express, Secure Computing         |
| HackerOne Account     | Registered as "Ruben Thomson" using handle "Deadcatx3"     |
+-----------------------+------------------------------------------------------------+

Direct Interview and Official Statements

Signal Interview with "Ellis" (Ruben Thomson)

Prior to his arrest, Thomson conducted a series of encrypted communications on Signal with investigative journalists, offering insight into his background, motives, and struggles with substance abuse.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Thomson described falling into malware development following stints in drug rehabilitation:

"One year ago I needed help monetizing some GitHub credentials. I was two months sober and needed a distraction and something to keep busy as well as people to speak to. I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances.

Blackhatting is fun. There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out."

When asked about his total financial earnings from the supply chain operations, Thomson claimed he received roughly $20,000, maintaining that financial gain was secondary to technical challenge and social connection. Addressing the prospect of law enforcement action, he expressed fatalism:

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

"If I’ve already been found out then it’s out of my control, I’ll make peace with that. Honestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this."

Chat logs from the Cybercats server and Telegram channels showed Thomson discussing heavy usage of ketamine, DMT, and synthetic psychedelics in the weeks leading up to his arrest, often disappearing for days following intense drug binges.

Industry and Expert Analysis

Security analysts emphasize that TeamPCP represents a shift in threat actor profiles, driven by lower barrier-to-entry exploitation tools.

Austin Larsen, Principal Threat Analyst at Google Threat Intelligence Group:

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

"TeamPCP is not a structured criminal crew with a single operator. It is a peer community of individually-skilled actors, with one clear center of gravity."

Charlie Eriksen, Security Researcher at Aikido Security:

"They are not a state actor, not quite organized cybercrime, and not purely ideological. Their motivations seem to mix money, disruption, attention, and ideology.

Historically, you had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets. Large language models have compressed that gap significantly. Threat actors can be noisy, they can make mistakes, they can leave evidence everywhere. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Law Enforcement Action and Legal Proceedings

On Wednesday morning, local time, law enforcement officers executed coordinated search warrants at residences in Western Australia. Thomson and Gaebler were taken into custody without incident.

The Australian Federal Police confirmed that the syndicate’s activities had impacted thousands of corporate networks worldwide. The defendants face a combined 14 charges under the Australian Criminal Code, including:

  • Unauthorized modification of data to cause impairment.
  • Unauthorized access to restricted data with intent to commit a serious offense.
  • Possession and production of cybercrime tools.

During their initial appearance at Perth Magistrates Court, Thomson was officially denied bail. Gaebler’s legal counsel did not submit a bail application. Both defendants have been remanded in custody pending their next scheduled court appearance on September 18.


Future Outlook and Ecosystem Impact

While TeamPCP’s core operations have been halted, their months-long campaign has permanently altered the landscape of open-source software security.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Policy and Infrastructure Remediation

In direct response to the devastation wrought by the Shai-Hulud worm, major code platforms have been forced to implement structural safeguards:

  • GitHub Dependabot Cooldowns: GitHub introduced a mandatory three-day cooldown period for Dependabot update requests. This mechanism delays automatic package version bumps, giving security researchers and automated scanners a time window to detect and neutralize poisoned updates before they are pulled into enterprise production environments.
  • Ecosystem-Wide Adoption: Coding ecosystems across Python (PyPI) and JavaScript (NPM) have begun integrating similar cooldown mechanisms (cooldowns.dev), institutionalizing delays for newly published package versions.
+-----------------------------------------------------------------------------------+
|                        SUPPLY CHAIN DEFENSE EVOLUTION                             |
+-----------------------------------------------------------------------------------+
| PRE-TEAMPCP ERA                                                                   |
| [Package Release] ────────────────────────────────────► [Immediate Auto-Update]   |
|                                                          (High Zero-Day Risk)     |
+-----------------------------------------------------------------------------------+
| POST-TEAMPCP ERA                                                                  |
| [Package Release] ──► [3-Day Cooldown Window] ─────────► [Verified Auto-Update]  |
|                       └─► Automated Scanning              (Risk Mitigated)        |
|                       └─► Community Auditing                                      |
+-----------------------------------------------------------------------------------+

The Legacy of TeamPCP

As Charlie Eriksen noted, TeamPCP’s legacy lies in its role as a destructive catalyst:

"They managed to wake up Microsoft to the fact that they had become negligent in terms of security. By compromising GitHub and stealing source code, they humiliated major tech maintainers into action, making them finally act on structural vulnerabilities that the security community had been raising for years."

The fall of TeamPCP underscores a new era in cybersecurity: one where small, loosely organized groups of individuals, leveraging AI tools and basic exploit frameworks, can inflict systemic disruption on global infrastructure—until their own digital footprints inevitably catch up with them.

Leave a Reply

Your email address will not be published. Required fields are marked *