In a landmark operation that has sent shockwaves through the global cybersecurity community, the Australian Federal Police (AFP) have dismantled a core segment of TeamPCP, a decentralized yet devastatingly effective cybercriminal syndicate. Two men, aged 21 and 23, were arrested in Western Australia this week, bringing an end to what security analysts describe as the longest-running and most audacious software supply chain attack spree in history.
The arrests—conducted in collaboration with the FBI and Western Australia Police—mark the culmination of a months-long investigation into a group that managed to poison the very foundation of modern software development. By weaponizing open-source code, TeamPCP didn’t just target businesses; they turned the collaborative nature of the internet against itself, compromising thousands of corporate environments and forcing a fundamental rethink of how software dependencies are trusted.

The Mechanics of Chaos: The Shai-Hulud Worm
TeamPCP’s notoriety stems from their development and deployment of Shai-Hulud, a self-propagating worm designed for the modern cloud-native era. Unlike traditional malware that relies on static payloads, Shai-Hulud was engineered to infiltrate the repositories of open-source developers.
The group’s methodology was described by Wired journalist Andy Greenberg as a "cyclical exploitation" of the software development ecosystem. The hackers would gain initial access to a developer’s network, often via phished GitHub or NPM credentials. Once inside, they would inject malicious code into a popular open-source tool. Because that tool was used by other developers to build their own software, the infection spread virally through the supply chain. This allowed TeamPCP to harvest credentials, cloud service keys, and intellectual property from thousands of organizations simultaneously.

Their reach was staggering. In March, they compromised LiteLLM, an AI gateway connecting users to over 100 large language models. A subsequent forensic analysis by the security firm CloudSEK revealed that this single breach exposed sensitive cloud keys and secrets across more than 2,500 organizations, including some of the world’s most prominent technology firms. By May, the group boasted that they had compromised at least 3,800 GitHub repositories.
Chronology of a Digital Insurgency
The ascent of TeamPCP was defined by a rapid evolution from opportunistic hacking to structured, albeit chaotic, criminal enterprise:

- Late 2025: TeamPCP emerges, marking their arrival by embedding malicious code into widely used open-source libraries.
- September 2025: The leader, operating under the alias "BulkDMT," advertises virtual private server (VPS) services on dark-web forums, signaling a shift toward monetizing infrastructure.
- March 2026: The group executes the LiteLLM attack, arguably their most damaging operation, resulting in mass credential theft across the AI infrastructure sector.
- May 2026: TeamPCP publishes the source code for Shai-Hulud 3.0, simultaneously launching a "recruitment contest" that offered $1,000 in Monero to hackers who could compromise the most popular code libraries.
- June 2026: Investigative journalists and security researchers, including Brian Krebs, begin mapping the real-world identity of the group’s leadership to individuals in Perth, Australia.
- August 2026: Australian law enforcement executes search warrants in Perth, resulting in the arrest of two men, later identified as Ruben Ian Thomson and Michael Gaebler.
Anatomy of the "Cybercats"
Security experts at Google Threat Intelligence emphasize that TeamPCP was not a traditional, hierarchical criminal organization. Instead, they functioned as a "peer community" of threat actors. At the center of this network was a Matrix chat server dubbed "Cybercats."
The group’s leadership—including the primary operator, known as "Kernelstub" (George Prepakis)—regularly used the server to coordinate attacks and share stolen data. The membership was a cross-section of the darker corners of the internet, including data breach brokers like "Boxturtle" (@xpl0itrsturtle), who trafficked in information stolen from automotive giants like BMW, Audi, and Honda.

The investigation into Ruben Thomson, the individual identified as the group’s primary spokesperson, revealed a startling lack of operational security (OPSEC). Despite his technical prowess, Thomson maintained a trail of digital breadcrumbs that led straight to his home in the beachside suburb of Cottesloe. His use of handles like "Deadcatx3" on a HackerOne bug-bounty profile—a moniker also linked to TeamPCP attacks—and his incorporation of companies with names like "OPSEC Express" served as the final nails in his digital coffin.
The Human Factor: Addiction and Ideology
Interviews conducted via Signal with the individual known as "Ellis" (Thomson) paint a portrait of a young, disillusioned developer caught in a cycle of substance abuse and radicalization. Ellis openly discussed his struggles with methamphetamine, ketamine, and DMT, often using these substances as a rationalization for his extended absences from the group’s operations.

More disturbing were the ideological undercurrents. The group’s inner circle featured members like @pcpcasper (Michael Gaebler), who was vocal in his support of neo-Nazi political organizations in Australia. For many in the group, the motivation was a toxic cocktail of financial desperation, a desire for "blackhat" notoriety, and a genuine, albeit twisted, sense of camaraderie forged in the trenches of illicit malware development.
Official Responses and Legal Consequences
The Australian Federal Police have been tight-lipped regarding the specifics of the evidence, but the charges are extensive. Both men face a combined 14 counts of cybercrime-related offenses. During a recent court appearance in Perth, it was confirmed that Thomson was denied bail, while Gaebler’s counsel did not pursue a release, ensuring both will remain in custody until at least their next appearance on September 18.

The arrests have been welcomed by the international security community, which has spent the better part of a year playing "whack-a-mole" with TeamPCP’s various iterations of malicious code.
Implications: The New Era of Supply Chain Security
The legacy of TeamPCP is paradoxical: they were a destructive force that simultaneously acted as a catalyst for overdue systemic change. Charlie Eriksen, a security researcher at Aikido Security, notes that the group achieved in months what the industry had failed to do for years: forcing platforms like GitHub to take supply chain security seriously.

"They humiliated Microsoft into action," Eriksen observed. In response to the Shai-Hulud threat, GitHub implemented a mandatory three-day "cooldown" period for Dependabot updates. This mechanism allows security researchers and maintainers a window of opportunity to detect compromised packages before they are automatically integrated into production environments.
Furthermore, TeamPCP’s use of AI tools to accelerate their attacks serves as a cautionary tale. Eriksen warns that we are entering an era where threat actors—even those with poor operational discipline—can operate at scale. "They can be noisy and make mistakes, but that doesn’t make them less dangerous," he said. "In some ways, it makes them more unpredictable."

As the dust settles on the arrests in Perth, the tech industry is left with a stark realization. The "Cybercats" were not a sophisticated state-sponsored intelligence agency, but a group of individuals using accessible, modern tools to exploit fundamental trust in the software ecosystem. The arrest of Thomson and Gaebler may have neutralized one major node of the network, but the underlying vulnerabilities they exploited remain. For developers and corporate security teams, the TeamPCP saga serves as a permanent reminder: in the world of open-source, trust must be verified, and the supply chain is only as secure as its weakest, most neglected link.
