The Fall of TeamPCP: How a Reckless Collective of "Cybercats" Triggered a Global Supply Chain Reckoning

In a landmark operation that has sent shockwaves through the global cybersecurity community, the Australian Federal Police (AFP) have dismantled the core of TeamPCP, a decentralized yet devastatingly effective cybercrime collective. The group, which spent the last year orchestrating the longest-running software supply chain attack spree in history, was finally silenced following the arrests of two Western Australian men, aged 21 and 23.

The suspects—identified through local reporting as Ruben Ian Thomson and Michael Gaebler—are alleged to have masterminded a series of breaches that compromised thousands of global businesses, siphoned cloud service keys, and forced a total re-evaluation of how open-source software is distributed and verified.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The Anatomy of an Unprecedented Campaign

TeamPCP emerged in late 2025, operating less like a traditional hierarchy and more like a fluid, toxic ecosystem of threat actors. Their primary weapon was Shai-Hulud, a self-propagating worm designed to infiltrate the infrastructure of open-source developers.

The group’s methodology was as ingenious as it was invasive. By compromising the credentials of developers on major platforms like GitHub and NPM, TeamPCP would inject malicious code into popular software libraries. When downstream developers downloaded these "updated" packages, the malware would install itself on their local machines, steal further credentials, and repeat the cycle. This "cyclical exploitation" allowed the group to exponentially expand their reach, eventually compromising thousands of corporate cloud environments.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The group’s audacity extended to their business model. In a surreal display of gamification, TeamPCP launched a recruitment contest in May 2026, offering $1,000 in Monero to the participant who could achieve the highest number of downloads for compromised packages. This was not merely a prank; it was a cold, calculated effort to identify and acquire high-value access at scale.

Chronology of a Digital Siege

  • 2022–2024: The foundation of the group’s infrastructure is laid. Early accounts linked to the aliases eventually used by TeamPCP (such as "XmasSnow" and "Sheep420") begin appearing on forums like Raidforums and Hackforums, often originating from IP addresses in Perth, Australia.
  • September 2025: The group begins to solidify its presence. The "Cybercats" Matrix chat server is established, becoming the nerve center for daily collaboration between multiple threat actors.
  • March 2026: A defining moment in the group’s history occurs when they compromise the AI gateway LiteLLM. The breach allows them to harvest cloud service keys from over 2,500 organizations, including major technology giants.
  • May 2026: TeamPCP gains notoriety by compromising 3,800 GitHub repositories, a move that forces the industry to confront the fragility of the "trusted publishing" model.
  • June 2026: Security researchers, including those at KrebsOnSecurity, begin connecting the digital dots, linking the "Deadcatx3" persona and the "EllisD25/BulkDMT" handles to a specific individual in Western Australia.
  • August 2026: Following an international investigation involving the FBI and the AFP, the two primary suspects are arrested in their Perth homes.

The "Cybercats" and the Erosion of Operational Security

The collapse of TeamPCP was not just a result of law enforcement prowess; it was the inevitable end of a group that defied the basic tenets of "OPSEC" (operational security).

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The group’s internal communication hub, the "Cybercats" Matrix server, served as a digital confession booth. Administrators like "Boxturtle" and "SeesawSec" boasted about their exploits, while the group’s leader, Ruben Thomson (operating under aliases like "Ellis" and "BulkDMT"), grew increasingly comfortable. Thomson’s personal failures were numerous: he registered companies with names derived from his hacker handles (such as "OPSEC Express"), reused passwords across both legitimate and criminal accounts, and left a trail of Google Maps reviews that pinpointed his physical location in the Perth suburb of Cottesloe.

Even more striking was the group’s volatility. The leaders frequently engaged in the use of hallucinogens—ketamine, DMT, and 2CB—often documenting their drug use and mental instability in public chats. This behavior, while seemingly erratic, provided investigators with the behavioral patterns necessary to track them in real-time.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Official Responses and Legal Proceedings

The AFP’s statement confirmed that the two men, Thomson and Michael Gaebler (alleged to be the individual behind the @pcpcasper alias), face a combined 14 cybercrime offenses. Following their initial appearance in Perth Magistrates Court, both men were denied bail and are currently being held in custody, with a return date set for September 18.

The legal action follows months of intelligence gathering. Security firms including Google Threat Intelligence, CloudSEK, and Intel 471 provided critical data linking the group’s residential IP addresses in Australia to the global supply chain attacks. The involvement of the FBI highlights the international scale of the threat; with thousands of American companies among the victims, the jurisdictional scope of the prosecution is likely to be expansive.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Implications: The New Era of Supply Chain Security

The legacy of TeamPCP is a permanent shift in how the software industry handles dependency management. Charlie Eriksen, a security researcher at Aikido Security, argues that TeamPCP acted as a violent catalyst for progress.

"They managed to wake up Microsoft to the fact that they had become negligent," Eriksen noted. "By compromising GitHub and exposing the ease with which supply chains can be poisoned, they humiliated the industry into adopting necessary safeguards."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

In direct response to the "Shai-Hulud" threat, GitHub and other major platforms implemented mandatory "cooldown" periods for package updates. This mechanism, which was previously treated as an optional best practice, is now a cornerstone of modern defensive architecture. It provides a vital window for security scanners to detect malicious code before it propagates across the developer ecosystem.

The Role of Artificial Intelligence

Perhaps the most significant takeaway from the TeamPCP case is the role of Artificial Intelligence in lowering the barrier to entry for cybercriminals. As Eriksen observed, the gap between "reading about an exploit" and "executing a campaign" has been compressed by LLMs.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

"You no longer need to be a world-class coder to orchestrate a global attack," Eriksen said. "These tools help actors troubleshoot, adapt, and scale their infrastructure. The result is a new breed of threat actor: one that is noisy, reckless, and prone to error, yet capable of causing damage that would have previously required a state-sponsored budget."

A Cautionary Tale

The story of Ruben Thomson—a young man who possessed the technical skill to threaten global commerce but lacked the maturity to maintain his own digital footprint—serves as a stark warning. The ease with which he was tracked from a "bug bounty" profile on HackerOne to his family’s dental practice in Australia underscores a fundamental truth of the modern digital age: no amount of sophisticated malware can protect a criminal who does not value their own anonymity.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

As the legal proceedings continue in Perth, the cybersecurity world is left to pick up the pieces of a fragmented software supply chain. TeamPCP may have been dismantled, but the vulnerabilities they exploited remain. The industry is now left with the arduous task of hardening the infrastructure that TeamPCP so ruthlessly brought to light, operating in a post-Shai-Hulud world where trust is no longer a default setting, but something that must be cryptographically proven.

For the victims—the 2,500+ companies compromised through LiteLLM and the countless others affected by the poisoning of open-source repositories—the arrest of the "Cybercats" provides little relief. The long-term damage of these breaches, involving the theft of cloud keys and internal secrets, will likely be felt for years to come as organizations scramble to rotate credentials and audit their environments for hidden, lingering backdoors.

Related Posts

Critical Stability Issues Identified in Windows Server 2025: Memory Management Changes Trigger Application Crashes

Microsoft has issued a formal warning to enterprise customers operating Windows Server 2025, cautioning that recent architectural changes to the operating system’s memory management subsystem are leading to significant stability…

The Rise of Autonomous Adversaries: How Hackers are Weaponizing Multi-Agent AI Frameworks

The landscape of cyber warfare is undergoing a tectonic shift. For years, the security community has tracked the evolution of AI-enhanced threats—from simple, prompt-engineered phishing emails to rudimentary code-generation assistants.…

You Missed

Redefining Hospitality: The Garden Hotel & Resort Becomes First Global Property to Integrate Full-Scale CLEAR Water Ecosystem

Redefining Hospitality: The Garden Hotel & Resort Becomes First Global Property to Integrate Full-Scale CLEAR Water Ecosystem

Powering the Future: A Landmark Partnership Between the World Sustainable Hospitality Alliance and the China Photovoltaic Industry Association

Powering the Future: A Landmark Partnership Between the World Sustainable Hospitality Alliance and the China Photovoltaic Industry Association

Waves of Change: OUTRIGGER Resorts & Hotels Celebrates Decade of Marine Stewardship

Waves of Change: OUTRIGGER Resorts & Hotels Celebrates Decade of Marine Stewardship

Redefining Luxury: World Sustainable Hospitality Alliance Takes Center Stage at Net Zero Summit

  • By Muslim
  • September 11, 2026
  • 5 views
Redefining Luxury: World Sustainable Hospitality Alliance Takes Center Stage at Net Zero Summit

The Future of Hospitality: Turning the Tide on Food Waste

The Future of Hospitality: Turning the Tide on Food Waste

From Intern to President: Michelle Woodley’s Blueprint for Modern Hospitality Leadership

From Intern to President: Michelle Woodley’s Blueprint for Modern Hospitality Leadership