Unmasking TeamPCP: Inside the Law Enforcement Takedown of the World’s Most Prolific Supply Chain Hacking Syndicate

Executive Overview

In a coordinated law enforcement operation spanning multiple continents, federal authorities in Australia, supported by the Federal Bureau of Investigation (FBI), have dismantled the core operational command of TeamPCP—a notorious cybercrime and data extortion collective responsible for the longest-running and most destructive software supply chain attack campaign in digital history.

The Australian Federal Police (AFP) and Western Australia Police Force (WAPF) executed early-morning arrest warrants in Perth, detaining two primary suspects: 21-year-old Ruben Ian Thomson of Cottesloe, identified as the group’s mastermind and primary spokesperson, and 23-year-old Michael Gaebler, an active participant tied to extremist movements and online extortion channels.

Operating at the intersection of open-source software exploitation, corporate credential theft, and aggressive data extortion, TeamPCP emerged in late 2025 to terrorize global software infrastructure. By deploying a self-propagating worm dubbed Shai-Hulud, the syndicate systematically compromised developer accounts across public repositories such as GitHub and NPM, leveraging infected building blocks to infiltrate thousands of downstream corporate networks.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
+-----------------------------------------------------------------------------------+
|                            TEAMPCP SYNDICATE TOPOGRAPHY                           |
+-----------------------------------------------------------------------------------+
|                                                                                   |
|  [ CORE LEADERSHIP ]                                                              |
|  Ruben Ian Thomson ("Ellis" / @pcpcats / BulkDMT) <---> Michael Gaebler (@pcpcasper)|
|                                 |                                                 |
|                                 v                                                 |
|  [ "CYBERCATS" MATRIX SERVER ] <---> George Prepakis (@kernelstub)                |
|           |                                                                       |
|           +---> Boxturtle / @xpl0itrsturtle (Auto Sector Breaches: BMW, Audi)     |
|           +---> SeesawSec / Fulcrumsec (Pharma/Data: Novo Nordisk, LexisNexis)    |
|                                                                                   |
|                                 | (Deploys Worm)                                  |
|                                 v                                                 |
|  [ INFRASTRUCTURE TARGETS ]                                                       |
|  * Shai-Hulud Worm (NPM / GitHub)  -->  3,800+ Repositories Compromised          |
|  * LiteLLM AI Gateway Breach        -->  2,500+ Corporate Secrets Harvested       |
+-----------------------------------------------------------------------------------+

The arrests mark the end of a high-stakes intelligence operation that mapped Thomson’s online digital footprint across darkweb forums, code repositories, and public business registries. Facing a combined 14 federal cybercrime offenses, the suspects remain in custody following a initial court appearance in Perth, leaving behind an industry scrambling to patch vulnerabilities exposed by their chaotic, high-volume assault on the global software supply chain.


Detailed Chronology

Late 2025: The Emergence of Shai-Hulud

TeamPCP burst onto the threat landscape in the final quarter of 2025. Unlike conventional ransomware operations that target perimeter network devices or phishing end-users, TeamPCP prioritized developer trust models.

The group unveiled Shai-Hulud, an automated, self-propagating supply chain worm. Operating discreetly, the worm harvested developer credentials stored locally on infected systems—specifically tokens for code platforms like GitHub, NPM, and PyPI—and used them to automatically publish compromised versions of popular open-source packages maintained by those developers.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

March 2026: The LiteLLM AI Supply Chain Breach

Recognizing the rapid enterprise adoption of artificial intelligence infrastructure, TeamPCP shifted focus toward critical AI middleware. In March 2026, the group executed a targeted supply chain attack against LiteLLM, an open-source AI gateway used to connect applications to more than 100 large language models (LLMs).

By injecting malicious code into the distribution line, TeamPCP effectively turned LiteLLM into a secret-harvesting conduit. Threat intelligence firm CloudSEK later revealed the attack extracted cloud service keys, API tokens, and continuous integration/continuous deployment (CI/CD) pipeline secrets from over 2,500 organizations, including top-tier Fortune 500 technology firms.

May 2026: GitHub Compromise and the $1,000 Recruitment Drive

By May 2026, TeamPCP claimed credit for compromising at least 3,800 individual repositories on Microsoft-owned GitHub. The breach was triggered when a senior GitHub developer installed a browser code extension covertly poisoned by TeamPCP’s malware.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
  +------------------------------------------------------------------+
  |              CYCLICAL SUPPLY CHAIN EXPLOITATION CYCLE            |
  +------------------------------------------------------------------+
  |                                                                  |
  |   [ Developer Downloads ] ---> [ System Compromised ]           |
  |     Poisoned Extension            Credentials Stolen             |
  |            ^                                |                    |
  |            |                                v                    |
  |   [ Automated Payload ]  <--- [ Malicious Versions ]             |
  |     Pushed to Repos             Published to Registry            |
  |                                                                  |
  +------------------------------------------------------------------+

Simultaneously, the group launched an unconventional recruitment campaign. Releasing Shai-Hulud v3.0, TeamPCP announced a gamified contest on Telegram, offering $1,000 in Monero ($XMR) to whichever outside participant executed the largest supply chain infection campaign using their worm.

According to rules analyzed by threat intelligence firm Dataminr, contestants were scored based on the monthly download counts of the packages they poisoned, incentivizing attacks against widely used software libraries.

"The $1,000 XMR prize is a recruitment floor and has been dismissed by the actor as 'just like a participation trophy,' adding 'if you find something good you will be paid way more,' confirming the contest's true function as talent identification and malicious access acquisition at scale."
— Dataminr Cyber Threat Intelligence Analysis

June–July 2026: Unravelling the OSINT Trail

Independent investigative reporting and threat intelligence tracking began closing in on TeamPCP’s core operators during the summer of 2026. A web of operational security (OPSEC) failures connected the group’s lead persona—known variously as "EllisD25," "BulkDMT," "Express," and "@pcpcats"—directly to 21-year-old Ruben Ian Thomson.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Direct communications between investigators and Thomson via encrypted channels took place throughout July, during which the suspect candidly detailed his history with drug addiction, lack of formal software engineering qualifications, and resignation to his eventual law enforcement arrest.

Late August 2026: Law Enforcement Intercept

On Wednesday morning, August 26, 2026, tactical teams from the AFP and Western Australia Police raided residences in Perth. Thomson and his 23-year-old co-conspirator, Michael Gaebler, were arrested. Both were formally charged in Perth Magistrates Court and remanded in custody pending further judicial proceedings.


Supporting Context & Metrics

The "Cybercats" Collective: Matrix Communication Networks

Security analysts emphasize that TeamPCP operated not as a rigid, top-down hierarchy, but as a node within a broader network of cybercrime actors.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
"It is not a structured criminal crew with a single operator. It is a peer community of individually-skilled actors, with one clear center of gravity."
— Austin Larsen, Principal Threat Analyst, Google Threat Intelligence Group

That center of gravity was hosted on an encrypted Matrix chat server dubbed Cybercats, created by security researcher and exploit developer George Prepakis (operating under the alias @kernelstub). The server brought together distinct criminal factions:

+------------------+-----------------------+--------------------------------------------------+
| Alias / Handle   | Matrix Identity       | Cybercrime Footprint / Primary Targets           |
+------------------+-----------------------+--------------------------------------------------+
| Boxturtle        | @xpl0itrsturtle       | Data breach broker (BMW, Audi, Honda, Toyota)    |
| SeesawSec        | Fulcrumsec            | Extortionist (Novo Nordisk, LexisNexis, Avnet)   |
| @pcpcasper       | Michael Gaebler       | TeamPCP core member / Neo-Nazi network affiliate |
| T / @pcpcats     | Ruben Ian Thomson     | TeamPCP lead / Shai-Hulud distributor            |
+------------------+-----------------------+--------------------------------------------------+

An Analysis of OPSEC Collapses

Ruben Thomson’s downfall serves as a textbook study in operational security degradation under the weight of persistent illicit activity and personal substance abuse.

+------------------------------------------------------------------------------------+
|                         CHRONOLOGY OF OPSEC DISINTEGRATION                         |
+------------------------------------------------------------------------------------+
|                                                                                    |
| [2018-2022] Early Cybercrime Activity                                             |
|   - Forum Registration: 'Yolosolo17' on Altenen registered via [email protected] |
|   - E-Commerce Domain: rubenthomson.com hosted on local Perth IP 110.141.230.15     |
|                                                                                    |
| [2022-2025] Infrastructure & Personal Account Overlaps                            |
|   - Shared Network: Home IP 211.27.196.111 linked to family file servers          |
|     (joshuawthomson39.myqnapcloud.com)                                             |
|   - Reused Credentials: '[email protected]' registered Raidforums account       |
|     'ChristmasSnow' using Perth residential ISPs                                  |
|   - Professional Footprint: Airbnb & Upwork profiles tied to [email protected]|
|                                                                                    |
| [2025-2026] TeamPCP Integration & Direct Alias Mapping                           |
|   - Business Registration: Australian company registered under 'OPSEC Express'    |
|     (Matching Breachforums handle 'Express')                                       |
|   - Bug Bounty Error: HackerOne account created under real name 'Ruben Thomson'    |
|     with the handle 'Deadcatx3'—a known TeamPCP malicious alias                    |
+------------------------------------------------------------------------------------+

The Human Dimension: Addiction and Nihilism

Throughout his online career, Thomson’s digital footprint was heavily intermingled with personal admissions regarding drug abuse and rehabilitation attempts. Posing on forums as "BulkDMT," Thomson disclosed struggles with methamphetamine, ketamine, and synthetic psychedelics.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

In private communications conducted via Signal prior to his arrest, Thomson expressed a sense of fatalism regarding his cybercrime trajectory:

"If I've already been found out then it's out of my control, I'll make peace with that. Honestly, I think someone like me needs a lot of help that prison just can't provide... Blackhatting is fun. There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out."
— Ruben Ian Thomson ("Ellis") in a July 2026 interview

Co-defendant Michael Gaebler (@pcpcasper) similarly compromised his identity by sharing domestic videos of his pet cat within Matrix chats—media metadata and localized environmental clues from which investigators pinpointed his location to Western Australia. Gaebler was also identified by authorities as an active participant in the National Socialist Network, an Australian neo-Nazi group.


Official Statements

Australian Federal Police Press Release

In a joint media statement alongside international law enforcement partners, the Australian Federal Police highlighted the global scale of the syndicate’s activity:

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
"This syndicate operated a sophisticated global cybercrime network that created malicious open-source software to rob thousands of businesses worldwide. The disruption of this group demonstrates that cybercriminals cannot hide behind encrypted servers or international boundaries. Australia will not serve as a safe haven for actors seeking to destabilize global digital infrastructure."
— Official Statement, Australian Federal Police (AFP)

Judicial Proceedings

Following their arrest on August 26, 2026, Thomson and Gaebler appeared before the Perth Magistrates Court.

  • Charges: Combined 14 counts of unauthorized modification of data to cause harm, access with intent to commit an offense, and commercial extortion.
  • Bail Status: Counsel for Gaebler made no application for bail. Thomson was formally denied bail due to flight risk concerns and potential access to encrypted digital assets.
  • Remand: Both defendants are remanded in custody awaiting their next formal hearing scheduled for September 18, 2026.

Future Outlook & Industry Impact

Lowering the Technical Bar: The Role of AI in Supply Chain Attacks

The legacy of TeamPCP has triggered a broader debate within the cybersecurity community regarding how emerging technology is compressing the time required to execute high-impact cyberattacks.

Charlie Eriksen, a threat researcher at security firm Aikido Security, notes that TeamPCP represented a novel category of threat actor: unaligned, ideologically fluid, and operating without traditional state-sponsored or organized crime safeguards.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
"They are not a state actor, not quite organized cybercrime, and not purely ideological. Their motivations seem to mix money, disruption, attention, and ideology. Historically, you had to understand research, adapt code, troubleshoot it, and build infrastructure. LLMs have compressed that gap significantly. Threat actors can be noisy, make mistakes, and take risks that professional groups wouldn't touch, but that doesn't make them less dangerous—it makes them more dangerous."
— Charlie Eriksen, Security Researcher, Aikido Security

Systematic Infrastructure Reforms: Cooldown Periods

TeamPCP’s high-volume abuse of software registries forced software ecosystem maintainers to implement security measures that had been stalled for years.

In direct response to the Shai-Hulud campaigns, GitHub announced a mandatory three-day "cooldown" mechanism for Dependabot—its automated dependency management system. Under this policy, automatically generated code updates for third-party libraries are delayed by 72 hours before being merged into production pipelines. This deliberate delay window grants automated threat-detection platforms and community maintainers crucial time to detect, flag, and remove compromised package versions before they can propagate down the supply chain.

+------------------------------------------------------------------------------------+
|                      POST-TEAMPCP SUPPLY CHAIN DEFENSE MODEL                       |
+------------------------------------------------------------------------------------+
|                                                                                    |
|  [ Developer Publishes Package ]                                                   |
|                |                                                                   |
|                v                                                                   |
|  [ Public Registry (NPM / PyPI / GitHub) ]                                         |
|                |                                                                   |
|                +---> [ 72-Hour Security Cooldown Window ]                          |
|                             |                                                      |
|                             +--> Automated Sandbox Scanning                        |
|                             +--> Anomaly Detection (Author Account Shifts)         |
|                             +--> Community Security Audits                         |
|                             |                                                      |
|                +------------+------------+                                         |
|                |                         |                                         |
|         (Threat Cleared)          (Malware Detected)                               |
|                |                         |                                         |
|                v                         v                                         |
|  [ Pushed to Dependabot ]         [ Package Revoked / Account Frozen ]             |
|                |                                                                   |
|                v                                                                   |
|  [ Enterprise Build Pipeline ]                                                     |
|                                                                                    |
+------------------------------------------------------------------------------------+

Similar safety guardrails have since been adopted by open-source governing bodies across Python (PyPI) and JavaScript ecosystems, marking a fundamental shift toward defensive friction in modern software engineering. While the prosecution of Thomson and Gaebler moves through the Australian court system, the architectural reforms provoked by TeamPCP’s chaotic spree will remain permanently embedded in the global software build pipeline.

Leave a Reply

Your email address will not be published. Required fields are marked *