In what law enforcement officials are calling a decisive blow against global cybercrime, the Australian Federal Police (AFP), working in tandem with the Federal Bureau of Investigation (FBI) and the Western Australia Police Force (WAPF), have arrested two young men in Perth, Western Australia. The defendants—21-year-old Ruben Ian Thomson and 23-year-old Michael Gaebler—stand accused of being central operatives in TeamPCP, a notoriously destructive cybercrime and data extortion syndicate responsible for the longest-running software supply chain attack campaign in history.
Operating at the intersection of open-source software exploitation, corporate extortion, and dark web access brokerage, TeamPCP emerged in late 2025 to inflict unprecedented disruption across global enterprise infrastructure. Powered by a self-propagating worm dubbed Shai-Hulud, the group systematically compromised software development repositories, harvesting credentials from cloud environments, continuous integration/continuous deployment (CI/CD) pipelines, and major technology vendors worldwide.
Despite the technical velocity of their campaigns—which impacted thousands of enterprise networks, artificial intelligence gateways, and automotive giants—the syndicate’s downfall was catalyzed by a series of catastrophic operational security (OPSEC) failures. An extensive open-source intelligence (OSINT) investigation, corroborated by direct interviews conducted by security researchers, tied the real-world identity of TeamPCP’s primary mastermind, known online as "Ellis" or "BulkDMT," directly to Thomson’s residential address and family network infrastructure in the affluent beachside suburb of Cottesloe.
Facing a combined 14 federal cybercrime charges, Thomson and Gaebler remain in custody following their initial court appearance in Perth. Their arrest marks the climax of a chaotic narrative defined by advanced malware deployment, drug-fueled darkweb operations, and a systemic wake-up call for the global software security ecosystem.
TeamPCP vaulted into the cybercrime spotlight in the final quarter of 2025. Unlike traditional ransomware operators who breach networks via phishing or perimeter vulnerabilities, TeamPCP targeted the trust boundaries of open-source software.
The group deployed the first version of Shai-Hulud, a malicious, self-propagating script designed to scan compromised environments for developer credentials, API tokens, and access keys tied to public code repositories like GitHub and NPM. Once obtained, these stolen credentials were used to insert malicious payloads into popular open-source packages, initiating a self-reinforcing infection cycle across downstream corporate applications.
2. Rapid Escalation and AI Supply Chain Attacks (March – May 2026)
By early 2026, TeamPCP shifted focus toward critical infrastructure components, particularly within emerging artificial intelligence frameworks:
March 2026 (LiteLLM Attack): The syndicate compromised LiteLLM, an open-source AI gateway managing integration between applications and over 100 large language models (LLMs). Security firm CloudSEK determined that this single supply chain breach harvested cloud keys and secrets from over 2,500 enterprise organizations, impacting an estimated 434,000 CI/CD pipelines.
May 2026 (GitHub Enterprise Exploitation): A developer at GitHub inadvertently installed a compromised extension, allowing TeamPCP malware to pivot into the platform’s internal ecosystem. The group claimed responsibility for breaching at least 3,800 code repositories hosted on the Microsoft-owned service.
May 2026 (The Shai-Hulud v3 Contest): Demonstrating an unconventional recruitment model, TeamPCP published the source code for the third iteration of Shai-Hulud online. They launched a crowdsourced competition offering $1,000 in Monero (XMR) to external hackers who could conduct the largest supply chain intrusion using their worm. Leaderboard scoring was tied directly to the monthly download volume of compromised packages, explicitly incentivizing attacks on high-profile, widely used software libraries.
3. The "Cybercats" Collective and Cross-Gang Nexus
Rather than functioning as a rigid hierarchical gang, TeamPCP operated as a central node in a broader ecosystem of threat actors. George Prepakis, an exploit developer operating under the handle @kernelstub, established a public Matrix chat server called Cybercats.
This chat server brought together high-profile operators from several distinct digital extortion groups:
Boxturtle (@xpl0itrsturtle / xpl0itrs): A breach broker linked to data leaks involving global automotive manufacturers (BMW Group, Audi, Honda, Mercedes-Benz, Volvo, Toyota) and consumer platforms such as Snapchat.
SeesawSec (Fulcrumsec): An extortionist responsible for intrusions targeting pharmaceutical giant Novo Nordisk, electronic distributor Avnet, and data broker LexisNexis.
@pcpcasper (Michael Gaebler): An active participant who frequently shared media linking him to Western Australia and expressed explicit affiliations with the National Socialist Network, an Australian neo-Nazi group.
T / @pcpcats (Ruben Thomson): The self-described primary spokesperson and technical lead for TeamPCP.
4. Unravelling the Leader: The Investigation and OPSEC Collapse
Despite employing advanced malware techniques, TeamPCP’s primary operator left a digital paper trail spanning nearly a decade across cybercrime forums, personal code repositories, and corporate filings.
Security researchers systematically mapped Thomson’s digital identity across multiple online aliases:
Forum Aliases: The handles EllisD25 (Darkforums), BulkDMT (Breachstars), and Express (Breachforums) were linked by shared Tox and Session IDs used to advertise "DMT Host," a virtual private server (VPS) bulletproof hosting operation.
Email Reuse: Breach data revealed that the handle Express registered accounts using [email protected]. Historical intelligence tied this address to another forum account, ChristmasSnow, registered from Perth-based IP addresses.
Home Infrastructure Leak: Passive DNS tracking of the home IP address (211.27.196.111) used by these accounts revealed active file servers bearing the family name, including joshuawthomson39.myqnapcloud.com. Open-source intelligence linked this host to the Thomson family, who migrated from Pietermaritzburg, South Africa, to Cottesloe, Western Australia.
The HackerOne Identity Flaw: In June 2025, Thomson created an account on the vulnerability disclosure platform HackerOne under his real name, "Ruben Thomson," while adopting the username Deadcatx3—an alias explicitly flagged by threat intelligence firms as belonging to TeamPCP’s core infrastructure maintainer.
Corporate Filings: Australian Securities and Investments Commission (ASIC) records confirmed that Ruben Ian Thomson registered multiple corporate entities in Western Australia, including Tensor Industries and OPSEC Express—the latter ironically incorporating his primary darkweb pseudonym into a formal business registry.
5. Pre-Arrest Signal Interviews and Law Enforcement Action
In early July 2026, independent investigative journalists established direct communication with Thomson via Signal. During these exchanges, Thomson acknowledged his history as a malware developer, his struggles with severe substance abuse (including methamphetamine, ketamine, and DMT), and his resignation regarding potential law enforcement action.
"If I’ve already been found out then it’s out of my control, I’ll make peace with that," Thomson stated during an interview, claiming he had stepped back from active operational duties in early 2026.
On the morning of Wednesday, August 26, 2026, officers from the AFP and WAPF executed simultaneous search warrants at residential addresses in Perth. Thomson and Gaebler were taken into custody without incident. In Perth Magistrates Court the following day, Thomson was formally denied bail, while Gaebler made no application for release. Both remain remanded in custody pending their next appearance on September 18, 2026.
Supporting Context & Metrics
The quantitative scale of TeamPCP’s supply chain interventions underscores the unprecedented systemic vulnerability of modern software dependency networks.
Quantifiable Operational Impact
Metric
Recorded Figure
Primary Target / Source
Enterprise AI Gateways Compromised
2,500+ Organizations
LiteLLM Gateway Attack
CI/CD Pipelines Exposed
~434,000 Pipelines
CloudSEK Supply Chain Audit
GitHub Repositories Breach Claims
3,800+ Repositories
Direct Compromise via Malicious Extension
Recruitment Prize Allocation
$1,000 Monero (XMR)
Shai-Hulud v3 Supply Chain Contest
Total Individual Criminal Charges
14 Federal Counts
Australian Federal Police Indictment
The Developer Exploitation Cycle
Writing for Wired, cybersecurity journalist Andy Greenberg detailed TeamPCP’s core operational methodology as a self-sustaining cycle of developer compromise:
┌────────────────────────────────────────────────────────────────────────┐
│ THE CYCLICAL EXPLOITATION MODEL │
└───────────────────────────────────┬────────────────────────────────────┘
│
┌───────────────────────────────┴───────────────────────────────┐
▼ ▼
[1. Access Acquisition] [2. Payload Injection]
Target developers via phished Embed Shai-Hulud worm into
credentials or compromised extensions. open-source packages/tools.
│ │
├───────────────────────────────◄───────────────────────────────┘
▼
[3. Downstream Propagation]
Malware executes on developer endpoints, harvesting local registry secrets.
│
▼
[4. Credential Harvesting & Expansion]
Exfiltrate GitHub/NPM tokens to publish new malicious package versions.
Access Acquisition: Operators breach a network hosting widely used open-source development software by targeting individual coders through credential harvesting or poisoned developer extensions.
Payload Injection: Malicious code (Shai-Hulud) is embedded silently into the source code of popular software libraries.
Downstream Propagation: Unsuspecting software engineers download the infected libraries into corporate environments, executing the malware on local workstations and CI/CD build servers.
Credential Exfiltration: The worm scans local memory, environment variables, and configuration files for repository tokens (GitHub, PyPI, NPM), transmitting them back to TeamPCP command-and-control servers to repeat the cycle at exponential scale.
Official Statements
Australian Federal Police (AFP)
In an official statement released following the Perth arrests, the AFP highlighted the international scope of the operation and the collaborative intelligence sharing that enabled the syndicate’s disruption:
"The AFP, in close coordination with our domestic and international law enforcement partners—including the FBI and Western Australia Police—has disrupted a highly sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses. Cybercriminals operating behind anonymous handles cannot evade justice indefinitely; our capabilities allow us to trace illicit activities through virtual networks straight to real-world front doors."
Cyber Threat Intelligence Perspective
Austin Larsen, Principal Threat Analyst with the Google Threat Intelligence Group, emphasized that TeamPCP represented a shift in organizational structure among modern threat actors:
"It is not a structured criminal crew with a single operator. It is a peer community of individually skilled actors, with one clear center of gravity. That decentralization allowed them to pivot quickly between targets, leveraging shared tools while operating across disparate sectors."
Charlie Eriksen, Security Researcher at Aikido Security, observed that artificial intelligence tools have radically altered the barrier to entry for high-impact cyber operations:
"Historically, there was a meaningful gap between reading about an attack technique and turning it into a reliable, operational campaign. You had to adapt code, troubleshoot infrastructure, and manage deployment across targets. Large language models have compressed that gap significantly. Threat actors can now operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability.
They can be noisy, they can make mistakes, and they can leave evidence everywhere. But that does not make them less dangerous. In some ways, it makes them vastly more unpredictable."
Future Outlook & Structural Industry Response
The legacy of TeamPCP’s campaign extends beyond the criminal proceedings facing Thomson and Gaebler. By directly attacking the foundation of software trust—public software dependency ecosystems—the group forced structural changes in how major tech conglomerates defend open-source infrastructure.
1. Mandatory Cooldown Mechanisms
In direct response to TeamPCP’s Shai-Hulud campaigns, Microsoft’s GitHub introduced a structural defense protocol in late July 2026: a mandatory three-day "cooldown" period for Dependabot, the platform’s automated dependency updating service.
┌────────────────────────────────────────────────────────────────────────┐
│ DEPENDABOT COOLDOWN PROTOCOL │
└───────────────────────────────────┬────────────────────────────────────┘
│
┌───────────────────────────────┴───────────────────────────────┐
▼ ▼
[New Package Version Released] [3-Day Mandatory Cooldown]
Author publishes version update Dependabot delays automated
to public registry (NPM/PyPI). pull request creation.
│ │
├───────────────────────────────◄───────────────────────────────┘
▼
[Automated & Community Auditing]
Security scanners examine code for Shai-Hulud-style payloads.
│
▼
[Safe Deployment]
If unflagged after 72 hours, update is cleared for enterprise deployment.
Under this policy, newly published versions of software packages are held in a staging window before Dependabot recommends or automatically deploys them to downstream projects. This delay provides automated security scanners and community maintainers a crucial window to detect and neutralize poisoned updates before they proliferate into enterprise build systems. Similar cooldown frameworks have subsequently been adopted across the Python (PyPI) and JavaScript ecosystems.
2. Paradigm Shift in Supply Chain Security
Security analysts argue that TeamPCP catalyzed reforms that the cybersecurity community had sought for years without success.
"They managed to wake up major platform providers to structural vulnerabilities in their security architecture," noted Aikido Security’s Charlie Eriksen. "By compromising development tools and accessing internal repositories, they forced platforms to act decisively on supply chain security rather than treating it as a secondary concern."
3. Conclusion
The collapse of TeamPCP serves as a stark case study in contemporary cyber warfare. It demonstrates how small, loosely affiliated groups of threat actors—equipped with modern developer tools and automation—can leverage open-source dependencies to inflict systemic damage on global enterprises.
Yet, it also highlights the persistent reality of digital criminality: regardless of how advanced a syndicate’s malware may be, operational indiscretions, recycled digital infrastructure, and basic human error remain the ultimate catalyst for law enforcement intervention. As Ruben Thomson and Michael Gaebler await trial in Western Australia, the software industry continues to rewrite its security protocols in the wake of their unprecedented campaign.