Dismantling TeamPCP: Inside the Fall of Cybercrime’s Most Prolific Supply Chain Syndicate

Executive Overview

In a milestone operation against global cybercrime, the Australian Federal Police (AFP), working alongside the Federal Bureau of Investigation (FBI) and the Western Australia Police Force (WAPF), have arrested two Western Australian men linked to TeamPCP. The syndicate is widely regarded by cybersecurity analysts as the perpetrator behind the longest-running and most disruptive software supply chain attack spree in history.

The suspects—21-year-old Ruben Ian Thomson of Cottesloe and 23-year-old Michael Gaebler—were apprehended in Perth and face a combined 14 cybercrime charges. Thomson, who operated under aliases including "Ellis," "EllisD25," "BulkDMT," "Express," and "Deadcatx3," is alleged to be the central operator and primary spokesperson of TeamPCP. Gaebler, identified online as "@pcpcasper," is an associate tied to the syndicate and reported to be an active member of the Australian neo-Nazi political group, the National Socialist Network.

TeamPCP rose to international prominence by embedding malicious payloads into hundreds of open-source software libraries. Leveraging self-propagating worm technology, automated credential harvesting, and targeted extortion, the group compromised thousands of corporate networks, cloud environments, and critical code repositories. Their targets spanned major technology entities, Fortune 500 electronics distributors, global pharmaceutical manufacturers, and automotive giants.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The syndicate’s unraveling was accelerated by an intricate web of digital breadcrumbs, severe operational security (OPSEC) failures, and extensive open-source intelligence (OSINT) tracing. The arrests mark a pivotal moment for open-source supply chain security, compelling major code-hosting platforms like GitHub to overhaul their defensive frameworks against rapid, automated dependency poisoning.


Detailed Chronology

+-----------------------------------------------------------------------------------+
|                            TEAMPCP INCIDENT TIMELINE                              |
+-----------------------------------------------------------------------------------+
| Late 2025    | Syndicate emerges; deploys "Shai-Hulud" supply chain worm.         |
| March 2026   | Breach of LiteLLM AI gateway (2,500+ orgs / 434k CI/CD pipelines).|
| May 2026     | Compromise of 3,800+ GitHub repositories; $1,000 XMR contest.     |
| June 2026    | Google Intelligence traces residential connections to South Africa. |
| July 2026    | GitHub introduces 3-day Dependabot cooldown response.             |
| August 2026  | Joint AFP-FBI raid leads to arrests of Thomson and Gaebler in Perth.|
+-----------------------------------------------------------------------------------+

Late 2025: The Emergence of TeamPCP and the Shai-Hulud Worm

TeamPCP emerged in late 2025, deploying a novel strategy that targeted the fundamental trust model of open-source software development. Rather than breaking directly into corporate perimeters, the group targeted individual software developers. By phishing credentials or stealing access tokens for public code repositories such as GitHub and the Node Package Manager (NPM), TeamPCP embedded malicious code directly into widely used open-source libraries.

Central to this initial campaign was Shai-Hulud, a self-propagating worm named after the mythical sandworms of science fiction. Once planted inside a developer’s environment, Shai-Hulud extracted saved credentials, cloud service keys, and access tokens. It then used those stolen privileges to commit malicious code to other software packages maintained by that developer, initiating a cyclical chain reaction of compromise across global developer ecosystems.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

March 2026: The LiteLLM Gateway Breach

In March 2026, TeamPCP shifted focus toward artificial intelligence infrastructure, executing a supply chain compromise of LiteLLM—an open-source AI gateway designed to bridge enterprise applications with over 100 large language models (LLMs).

By poisoning the LiteLLM source code, TeamPCP established persistent access inside thousands of corporate continuous integration and continuous delivery (CI/CD) pipelines. Cybersecurity analytics firm CloudSEK later confirmed that this single attack harvested sensitive API keys, cloud infrastructure secrets, and database credentials from more than 2,500 enterprise organizations worldwide.

May 2026: Mass Scale Repositories Breaches and Crowdsourced Exploitation

By May 2026, TeamPCP achieved another breach by compromising a browser extension used by an engineer at Microsoft-owned GitHub. This single entry point enabled the syndicate to compromise at least 3,800 GitHub repositories, embedding backdoors and extracting environment variables.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Concurrently, TeamPCP released the source code for the third iteration of the Shai-Hulud worm and launched a public hacking contest. The group offered $1,000 in Monero (XMR) to external cybercriminals who could orchestrate the largest supply chain operation using the worm. Contestants were scored based on the weekly and monthly download metrics of the packages they infected—directly incentivizing hackers to target high-traffic software libraries. Security firm Dataminr identified the contest as a talent acquisition drive to recruit skilled threat actors and purchase access to breached infrastructure at scale.

+---------------------------------------------------------------------------------+
|                       TEAMPCP CYCLICAL EXPLOITATION CYCLE                       |
+---------------------------------------------------------------------------------+
|                                                                                 |
|   [ 1. Phish/Steal Developer Credentials (GitHub / NPM / Browser Extensions) ]   |
|                                        │                                        |
|                                        ▼                                        |
|   [ 2. Plant Malicious Payload / Shai-Hulud Worm in Open-Source Libraries ]    |
|                                        │                                        |
|                                        ▼                                        |
|   [ 3. Package Downloaded by Downstream Developers & CI/CD Pipelines ]          |
|                                        │                                        |
|                                        ▼                                        |
|   [ 4. Extract API Keys, Cloud Secrets, and Maintainer Tokens ]                |
|                                        │                                        |
|                                        └──────────────────────────────────────┐ |
|                                                                               │ |
|   [ 5. Monolith Extortion / Code Leakage / Further Worm Propagation ] ◄───────┘ |
|                                                                                 |
+---------------------------------------------------------------------------------+

June–August 2026: OSINT Deep Dives and Federal Enforcement

Throughout mid-2026, independent intelligence researchers and corporate security teams systematically dismantled the operational anonymity of TeamPCP’s leadership. Google Threat Intelligence traced residential and mobile network connections linked to the attacks to South Africa and Perth, Western Australia.

By August 2026, law enforcement agencies executed coordinated search warrants in Western Australia, taking Ruben Ian Thomson and Michael Gaebler into custody and seizing technical infrastructure used to manage the syndicate’s extortion leak sites.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Supporting Context & Metrics

Quantitative Impact and Attack Metrics

The financial and operational scope of TeamPCP’s supply chain attacks stands among the largest recorded in recent cybersecurity history:

Impacted Vector / Metric Extent of Intrusion / Damage Key Victims & Entities Affected
Enterprise AI Infrastructure 2,500+ Organizations; 434,000 CI/CD Pipelines LiteLLM userbase, global technology firms
Code Repositories Poisoned 3,800+ GitHub Repositories Microsoft/GitHub infrastructure & third-party devs
Automotive Data Leaks Multi-Gigabyte Proprietary Databases BMW Group, Audi, Honda, Mercedes-Benz, Volvo, Toyota
Corporate & Tech Targets Data Extortion & Cloud Breaches Snapchat, SportRadar, Novo Nordisk, LexisNexis, Avnet
Syndicate Recruitment Drive $1,000 Monero base prize + tier payouts Public download-driven dependency poisoning

The "Cybercats" Syndicate Model

Security analysts emphasize that TeamPCP operated not as a rigid, top-down criminal enterprise, but as a decentralized federation of threat actors. Austin Larsen, principal threat analyst at Google Threat Intelligence Group, described TeamPCP as a "peer community of individually-skilled actors, with one clear center of gravity."

This center of gravity coalesced around a Matrix chat server designated Cybercats, established by security researcher and exploit developer George Prepakis (operating online as @kernelstub). The Cybercats network served as an operational hub connecting distinct cybercrime entities:

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
  • xpl0itrs / Boxturtle (@xpl0itrsturtle): Acted as a primary data breach broker across platforms such as Breachforums, offering stolen corporate intelligence from global automakers.
  • Fulcrumsec / SeesawSec: Responsible for targeted corporate data extortion against healthcare and technology entities, including Novo Nordisk and LexisNexis.
  • @pcpcasper (Michael Gaebler): An associate who posted operational updates alongside extremist political messaging tied to the Australian National Socialist Network.
  • @pcpcats / Ellis (Ruben Ian Thomson): Served as the public face, technical coordinator, and primary administrator for TeamPCP operations.
+---------------------------------------------------------------------------------+
|                       CYBERCATS MATRIX CHAT NETWORK MATRIX                      |
+---------------------------------------------------------------------------------+
|                                                                                 |
|                        [ George Prepakis (@kernelstub) ]                        |
|                                (Server Founder)                                 |
|                                       │                                         |
|         ┌─────────────────────────────┼─────────────────────────────┐           |
|         ▼                             ▼                             ▼           |
|  [ Ruben Thomson ]            [ Michael Gaebler ]           [ Boxturtle ]       |
|   "Ellis / Express"            "@pcpcasper"               "xpl0itrs"            |
|   (TeamPCP Lead)              (Extremist/Affiliate)      (Data Breach Broker)   |
|         │                             │                             │           |
|         ▼                             ▼                             ▼           |
| • Shai-Hulud Worm             • Propaganda Sharing          • BMW, Audi, Honda  |
| • GitHub Breaches             • Perth Geo-location          • Snapchat Breaches |
| • Corporate Extortion                                                           |
|                                                                                 |
+---------------------------------------------------------------------------------+

Unmasking "Ellis": Anatomy of an OPSEC Breakdown

Despite utilizing sophisticated software supply chain attack vectors, Thomson’s real-world identity was uncovered due to long-running operational security oversights:

  1. Reused Digital Handles and Contact Profiles: The online personas EllisD25, BulkDMT (associated with "DMT Host," a virtual private server service), and Express cross-referenced identical Session and Tox messaging IDs on underground cybercrime forums.
  2. IP and Domain Records: Registration details for the Breachforums account Express used the email address [email protected]. Historical data showed this address was previously registered to an account named ChristmasSnow on Raidforums, accessed almost exclusively via Perth-based internet service providers.
  3. Passive DNS Correlations: Passive DNS analysis linked a Perth residential IP address (211.27.196.111) to private local network devices, including a QNAP storage server registered under joshuawthomson39.myqnapcloud.com.
  4. Social & Identity Cross-Referencing: Public breach data connected the family network to an email address ([email protected]), which shared identical passwords with accounts on hacking forums like Altenen (Yolosolo17). Corporate registries revealed Thomson had registered multiple Western Australia businesses, including one named OPSEC Express—directly mirroring his dark web handle Express.
  5. Direct Handle Collisions: In June 2025, Thomson created an account on the bug bounty platform HackerOne under his legal name, selecting the handle Deadcatx3—a handle previously cited in threat intelligence reports as an active TeamPCP indicator of compromise.

The Human Dimension: Substance Abuse and Direct Admissions

In direct Signal communications conducted with investigative reporters prior to his arrest, Thomson openly acknowledged his history of severe substance abuse, housing instability, and criminal activity. Thomson claimed he initially turned to malware development as a distraction following detox programs.

"Blackhatting is fun. There are actual rewards and incentives to learn and you grow with your team. 
Without qualifications, no employer will even take the time to hear you out... Honestly, I think 
someone like me needs a lot of help that prison just can't provide."
                                 — Ruben Ian Thomson ("Ellis") in interview prior to arrest

Chat logs retrieved from the Cybercats Matrix server revealed chronic usage of hallucinogens, ketamine, and synthetic psychedelics (such as 2C-B and DMT), which frequently resulted in multi-day absences and operational neglect—further accelerating the group’s vulnerability to law enforcement monitoring.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Official Statements

Australian Federal Police (AFP) Statement

In an official statement released following the Perth operations, the Australian Federal Police highlighted the international coordination required to dismantle the group:

"The AFP, working alongside our federal and international partners including the FBI, has dismantled a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses. Cybercriminals operating within Australia’s borders cannot hide behind pseudonyms or encrypted communications. These arrests demonstrate that law enforcement possesses both the technical capabilities and global reach required to track down and prosecute those who threaten international digital infrastructure."

Media Confirmation and Judicial Proceedings

Reporting by Australia’s ABC News confirmed the court appearance details for the defendants following their initial hearing in the Perth Magistrates Court:

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

ABC News Report Excerpt:
"Ruben Ian Thomson, 21, of Cottesloe, appeared in Perth Magistrates Court charged with multiple count cybercrime offenses following an extensive international investigation. Thomson was formally denied bail. Co-defendant Michael Gaebler, 23, also faced charges; his legal representation made no application for bail. Both men have been remanded in custody pending their next scheduled court appearance on September 18."


Future Outlook

AI Compression of the Vulnerability Gap

The case of TeamPCP highlights a shift in the modern threat landscape: the integration of Artificial Intelligence and Large Language Models into cybercrime workflows.

Charlie Eriksen, security researcher at Aikido Security, noted that historically a structural gap existed between reading about an exploit concept and executing a global attack campaign. "You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets," Eriksen explained. "LLMs have compressed that gap significantly."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

This technological compression allows low-discipline threat actors to launch automated attacks at scale. While these actors may lack traditional operational discipline—frequently leaving digital evidence—the scale of their automated attacks can cause widespread institutional damage.

+---------------------------------------------------------------------------------+
|             TRADITIONAL VS. AI-COMPRESSED ATTACK CYCLES                        |
+---------------------------------------------------------------------------------+
|                                                                                 |
| TRADITIONAL ATTACK LIFECYCLE:                                                   |
| [ Vulnerability Research ] ──► [ Custom Exploit ] ──► [ Manual Infrastructure ]  |
| 🕒 Requires months of development and operational discipline.                    |
|                                                                                 |
| AI-COMPRESSED ATTACK LIFECYCLE (TEAMPCP ERA):                                   |
| [ LLM-Assisted Code Adapt ] ──► [ Automated Worm ] ──► [ Mass API Exploitation ]|
| ⚡ Executed in days by low-OPSEC actors operating at massive scale.              |
|                                                                                 |
+---------------------------------------------------------------------------------+

Institutional Defense Shift: Package Cooldown Mechanisms

TeamPCP’s campaign forced major changes in open-source security standards. The group’s compromise of GitHub systems pressured repository maintainers to deploy automated defense mechanisms.

In late July 2026, GitHub implemented a three-day cooldown period for Dependabot—the platform’s automated system for fetching software dependency updates. Cooldown mechanisms temporarily delay the automated installation of newly published package versions, providing security scanners and open-source maintainers time to detect and isolate poisoned software releases before they reach downstream corporate environments.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
+---------------------------------------------------------------------------------+
|                    DEPENDABOT THREE-DAY COOLDOWN MECHANISM                      |
+---------------------------------------------------------------------------------+
|                                                                                 |
|   [ Developer Publishes New Package Version (e.g., v1.0.4) to Registry ]        |
|                                        │                                        |
|                                        ▼                                        |
|   [ DEPENDABOT COOLDOWN TIMER ACTIVATED (Day 1 to Day 3 Hold) ]                  |
|                                        │                                        |
|      ┌─────────────────────────────────┴────────────────────────────────┐       |
|      ▼                                                                  ▼       |
|  ( Malicious Code Detected )                                   ( Package Clean )    |
|      │                                                                  │       |
|      ▼                                                                  ▼       |
|  [ Package Quarantined & Revoked ]                     [ Auto-Merged to Prod ]  |
|                                                                                 |
+---------------------------------------------------------------------------------+

This safety standard has since gained traction across other major developer ecosystems, including the Python Package Index (PyPI) and JavaScript package registries via standardized cooldown initiatives (cooldowns.dev).

Long-Term Industry Implications

The prosecution of Thomson and Gaebler underscores the urgent need for enterprise security strategies that address open-source supply chain vulnerabilities. As development pipelines increasingly rely on third-party libraries and automated integration tools, security architectures must evolve from perimeter defense to continuous dependency verification. While the dismantling of TeamPCP removes a prominent threat syndicate, the automated methodologies they popularized remain a major challenge for modern digital infrastructure.

Leave a Reply

Your email address will not be published. Required fields are marked *