Inside the Takedown of TeamPCP: How Law Enforcement Unmasked the Masterminds Behind the Largest Software Supply Chain Attack Spree

Executive Overview

In a milestone international law enforcement operation, the Australian Federal Police (AFP), working in close coordination with the Federal Bureau of Investigation (FBI) and the Western Australia Police Force (WAPF), has dismantled the primary operational core of TeamPCP. The prolific cybercrime and data extortion syndicate is widely credited with engineering the longest-running, most aggressive software supply chain attack spree in cybersecurity history.

Following coordinated raids in Western Australia, authorities arrested two men: 21-year-old Ruben Ian Thomson of Cottesloe and 23-year-old Michael Gaebler. Facing a combined 14 cybercrime offenses in the Perth Magistrates Court, the duo stands accused of developing and propagating malicious open-source software packages that breached thousands of enterprise networks globally, compromised corporate cloud environments, and harvested sensitive cryptographic credentials at an unprecedented scale.

Thomson, who operated online under aliases such as "Ellis," "EllisD25," "BulkDMT," "Express," and "@pcpcats," served as the de facto spokesperson and operational lead for TeamPCP. Gaebler, known online as "@pcpcasper" and identified by investigators as an active member of the Australian neo-Nazi group National Socialist Network, worked alongside Thomson within a sprawling digital ecosystem of threat actors.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Despite employing sophisticated automated propagation techniques—including the self-spreading worm known as Shai-Hulud—the syndicate was ultimately brought down by a series of catastrophic operational security (OPSEC) failures. Digital breadcrumbs left across cybercrime forums, domestic IP addresses linked to home file servers, business registry filings under real names, and open admissions made during private interviews with investigative reporters allowed authorities and independent researchers to unmask the group’s leadership.


Detailed Chronology

[Late 2025] ----------------> [March 2026] --------------> [May 2026] -----------------> [July–August 2026]
TeamPCP Emerges;             LiteLLM AI Gateway            GitHub Breach (3,800 Repos);  Dependabot Cooldowns Implemented;
Shai-Hulud Worm Deployed     Breached (2,500+ Orgs)        Shai-Hulud v3.0 Contest        AFP/FBI Arrest Thomson & Gaebler

1. Emergence and the Shai-Hulud Engine (Late 2025)

TeamPCP burst into public view in late 2025, deploying a self-propagating worm dubbed Shai-Hulud. Unlike traditional malware that targets end-user endpoints directly, Shai-Hulud was engineered to exploit the fundamental trust underlying modern open-source software development.

The worm operated through a cyclical chain of infection:

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
  1. Initial Phishing/Credential Theft: Hackers harvested developer credentials for public code repositories like GitHub and the Node Package Manager (NPM).
  2. Package Poisoning: Malicious code was embedded into legitimate, widely used open-source libraries.
  3. Automated Spread: When downstream developers downloaded the infected packages into their environments, the embedded payload executed silently, stealing local credentials, SSH keys, and cloud access tokens.
  4. Repository Hijacking: Using the newly stolen credentials, Shai-Hulud automatically published infected updates to any code repositories maintained by the newly compromised developers, exponentially expanding the group’s reach.

2. The AI Infrastructure Hijack (March 2026)

In March 2026, TeamPCP escalated its operations by executing a high-impact supply chain attack against LiteLLM, an open-source artificial intelligence gateway used to connect applications to more than 100 large language models (LLMs). By inserting malicious code into the LiteLLM codebase, TeamPCP weaponized thousands of continuous integration and continuous delivery (CI/CD) pipelines.

Subsequent technical analyses revealed that this single breach harvested active cloud service keys, API tokens, and corporate secrets from more than 2,500 organizations, including some of the world’s largest technology enterprises.

3. Mass Breach of GitHub Repositories (May 2026)

By May 2026, TeamPCP compromised a browser extension utilized by a developer at GitHub (a Microsoft subsidiary). The access allowed the syndicate to breach and poison at least 3,800 code repositories hosted on the platform.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Concurrently, TeamPCP released the source code for Shai-Hulud 3.0 and launched a public cybercrime competition. The group offered a $1,000 prize in Monero (XMR) to whichever external threat actor could execute the largest supply chain infection using their worm framework. Contestants were scored based on the total weekly and monthly download counts of the packages they successfully poisoned, directly incentivizing attacks against popular, high-volume software libraries.

4. The "Cybercats" Communications Hub

Throughout early and mid-2026, TeamPCP operated within a loose confederation of cybercriminals communicating on a private Matrix chat server named "Cybercats." Created by security researcher and exploit developer George Prepakis ("@kernelstub"), the chat room served as a central meeting point for distinct cybercrime entities:

  • Boxturtle (@xpl0itrsturtle): A data broker selling stolen databases from major automotive manufacturers, including BMW Group, Audi, Honda, Mercedes-Benz, Volvo, and Toyota.
  • SeesawSec (Fulcrumsec): An extortion actor responsible for data theft attacks against Novo Nordisk, LexisNexis, and Avnet.
  • @pcpcasper (Michael Gaebler): Operational contributor linked to neo-Nazi political networks in Australia.
  • T / @pcpcats (Ruben Ian Thomson): Primary administrator, author of the Shai-Hulud infrastructure, and group spokesperson.

5. Law Enforcement Intervention (August 2026)

Following months of international tracking and open-source intelligence gathering, the Australian Federal Police executed simultaneous search warrants in Western Australia. Thomson and Gaebler were taken into custody without incident, effectively neutralizing TeamPCP’s primary operational hub.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Supporting Context & Metrics

Unmasking the Syndicate: A Masterclass in Operational Failures

While TeamPCP displayed advanced technical mechanics in automated software supply chain compromise, the group’s leadership suffered from systemic operational security blunders that allowed researchers and federal agents to trace their real-world identities.

+-----------------------------------------------------------------------------------+
|                           RUBEN IAN THOMSON (Ellis)                               |
+-----------------------------------------------------------------------------------+
  |-- Email Trail: [email protected] -> [email protected] -> [email protected]
  |-- IP Artifacts: Perth Home IP (211.27.196.111) hosting Synology/QNAP Family Server
  |-- Real Name Leaks: HackerOne account "Ruben Thomson" (Handle: Deadcatx3)
  |-- Commercial Filings: ASIC Business Registrations for "OPSEC Express" & "Tensor Industries"
  +-- Digital Footprint: Google Maps reviews tied to Perth; TikTok account linked to personal phone

The Digital Breadcrumb Trail

  1. Email and Forum Correlation: Thomson utilized the alias "Express" on Breachforums, registering with the email address [email protected]. Historical breach data tied this email to an older Raidforums account named ChristmasSnow, accessed predominantly from Perth-based ISP addresses.
  2. Home Network Leakage: Passive DNS data linked these Perth IP addresses directly to network-attached storage (NAS) devices operated by the Thomson family, including hostnames such as joshuawthomson39.myqnapcloud.com and thomsonfamily.net.au.
  3. The HackerOne Blunder: In June 2025, Thomson registered an account on the bug-bounty platform HackerOne using his real name, Ruben Thomson, while assigning himself the handle Deadcatx3—an alias explicitly flagged by threat intelligence firms as a primary TeamPCP identifier.
  4. Commercial Entity Registration: In an extraordinary lapse of OPSEC, Thomson registered several Australian corporations through the Australian Securities and Investments Commission (ASIC), including Secure Computing Solutions, Tensor Industries, and OPSEC Express—incorporating his primary dark web forum handle directly into official state documentation.
  5. Geographical and Social Footprints: Gaebler (@pcpcasper) frequently posted images and videos of his pet cat in group chats. Embedded metadata and background visual cues placed the media directly in Western Australia.

Human Factors: Substance Abuse and Direct Admissions

In private interviews conducted via Signal weeks prior to his arrest, Thomson ("Ellis") offered candid insights into his motivations, history, and personal decline. Thomson described a background marred by severe substance abuse—including chronic addiction to methamphetamine, ketamine, DMT, and 2C-B—as well as periods of homelessness.

"Blackhatting is fun. There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out. If I’ve already been found out then it’s out of my control, I’ll make peace with that… Honestly, I think someone like me needs a lot of help that prison just can’t provide."
Ruben Ian Thomson ("Ellis") in an interview prior to his arrest

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Thomson claimed he had stepped back from active operations in March 2026, though intelligence logs showed he remained in continuous communication with active extortionists until his arrest.

Systemic Impact Metrics

The physical and digital reach of TeamPCP’s activities spans major corporate, financial, and technological sectors:

Target/Metric Scale of Impact Primary Exploitation Vector
LiteLLM Compromise 2,500+ Enterprises / 434,000 CI/CD Pipelines Poisoned Open-Source AI Gateway
GitHub Repositories 3,800+ Repositories Breached Stolen Developer Extension Credentials
Shai-Hulud Worm Reach Hundreds of NPM / PyPI Packages Automated Credential Scraping & Re-publishing
Automotive Breaches 6 Global OEMs (BMW, Audi, Honda, etc.) Network Intrusions via Associated Brokers
Facing Charges 14 Cybercrime Counts AFP / FBI Joint Task Force Indictments

Official Statements

Australian Federal Police (AFP)

In a formal press briefing, AFP authorities emphasized the global scope of the group’s actions and the vital nature of cross-border law enforcement collaboration:

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

"These arrests demonstrate that anonymity on the internet is an illusion. Working alongside our international partners at the FBI, we have dismantled a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses. The scale of victimology across critical technology infrastructure made this group a top priority for global law enforcement."

Threat Intelligence & Industry Experts

Austin Larsen, Principal Threat Analyst, Google Threat Intelligence Group:

"TeamPCP is less of a structured criminal crew with a single operator and more of a peer community of individually skilled actors, with one clear center of gravity. That center was built around persistent, automated exploitation of developer environments."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Charlie Eriksen, Security Researcher, Aikido Security:

"They are not a state actor, not quite organized cybercrime, and not purely ideological. Their motivations seem to mix money, disruption, attention, and ideology. Historically, there was a gap between reading about an attack technique and turning it into an operational campaign. Large language models (LLMs) have compressed that gap significantly.

Threat actors can now operate at massive scale without having developed the traditional operational discipline. They can be noisy, make mistakes, and leave evidence everywhere, but that does not make them less dangerous. In some ways, it makes them more dangerous."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Future Outlook

The arrest of TeamPCP’s core operators marks a critical turning point in the defense of open-source software infrastructure. However, the technical legacy of their campaigns has permanently altered how software package repositories handle security controls.

                    ┌────────────────────────────────────────┐
                    │      SHAI-HULUD SUPPLY CHAIN IMPACT     │
                    └───────────────────┬────────────────────┘
                                        │
                                        ▼
             ┌────────────────────────────────────────────────────┐
             │ Automated Poisoning of Open-Source Repositories    │
             └──────────────────┬─────────────────────────────────┘
                                │
                                ▼
             ┌────────────────────────────────────────────────────┐
             │ Industry Realization of Dependency Pipeline Risks   │
             └──────────────────┬─────────────────────────────────┘
                                │
                                ▼
┌──────────────────────────────────────────────────────────────────────────────┐
│                    PERMANENT INDUSTRY COUNTERMEASURES                        │
├──────────────────────────────────────────────────────────────────────────────┤
│ 1. Mandatory 3-Day Cooldowns on Automated Updates (GitHub Dependabot)       │
│ 2. Automated Token Invalidation for Exposed Dev Credentials                  │
│ 3. Widespread Ecosystem Adoption Across PyPI, NPM, and RubyGems              │
└──────────────────────────────────────────────────────────────────────────────┘

Institutional Reforms to Software Repositories

In direct response to TeamPCP’s exploits, major code repository providers have introduced structural shifts in package management:

  • Mandatory Update Cooldowns: GitHub implemented a mandatory three-day "cooldown" mechanism for Dependabot—its automated dependency update tool. When a developer releases a new package version, automated systems delay pushing the update to downstream users for 72 hours, providing security automated scanners and the developer community a window to detect potential supply chain poisoning.
  • Cross-Ecosystem Adoption: Python (PyPI), JavaScript (NPM), and Rust (Crates.io) ecosystems have begun adopting similar cooldown frameworks and strict multi-factor authentication (MFA) requirements for package maintainers.

The Changing Landscape of AI-Enabled Cybercrime

The TeamPCP saga serves as a case study for the modern threat landscape, where low-discipline actors can leverage modern artificial intelligence and automated frameworks to punch far above their weight class. While the removal of Thomson and Gaebler neutralizes TeamPCP’s immediate operations, law enforcement agencies worldwide are bracing for similar, AI-accelerated supply chain threats operated by decentralized networks of actors.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Thomson and Gaebler remain in custody in Western Australia following the denial of bail. Both defendants are scheduled to stand trial at Perth Magistrates Court as joint international investigations continue into their global network of cybercrime associates.

Leave a Reply

Your email address will not be published. Required fields are marked *