The Rise and Fall of TeamPCP: Inside the Supply Chain Saboteurs Who Humiliated Big Tech

In a landmark operation that has sent shockwaves through the global cybersecurity community, the Australian Federal Police (AFP) have dismantled the core of TeamPCP, an elusive and highly disruptive cybercriminal syndicate responsible for what experts describe as the most persistent and damaging software supply chain attack spree in history.

Following an intensive multi-agency investigation involving the FBI and Western Australia Police, authorities arrested two men, aged 21 and 23, in Perth. The suspects are alleged to have spearheaded a global operation that weaponized open-source software, compromising thousands of businesses by poisoning the very code libraries that power the modern internet. While the AFP has not publicly named the defendants, official records and investigative reporting have confirmed the identities of the primary targets as Ruben Ian Thomson and Michael Gaebler.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The arrests mark the end of a chaotic, nine-month reign of terror that saw TeamPCP leverage advanced automation, hallucinogenic-fueled bravado, and a complete disregard for operational security (OPSEC) to breach high-value targets, including the AI infrastructure of major technology conglomerates.


A Chronology of Chaos: The “Shai-Hulud” Era

TeamPCP’s entry into the cybercrime ecosystem in late 2025 was marked by an aggressive and innovative approach to software supply chain infiltration. Their primary tool, a self-propagating worm dubbed "Shai-Hulud," was designed to turn the collaborative nature of open-source development against itself.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The Cyclical Exploitation Model

As detailed by journalist Andy Greenberg in Wired, TeamPCP utilized a "cyclical" attack strategy. By gaining initial access to a developer’s environment—often through phished credentials for platforms like GitHub or NPM—the group would inject malicious code into a widely used open-source tool.

Once that compromised tool was downloaded by other developers, it would inadvertently install the Shai-Hulud malware on their machines. This allowed the hackers to harvest credentials from those developers, which were then used to publish further malicious updates to other software tools. It was a self-sustaining loop of infection that allowed the group’s footprint to expand exponentially across global corporate networks.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The “Cybercats” Contest

In a bizarre display of arrogance, TeamPCP transitioned from professional-grade exploitation to a form of gamified recruitment in May 2026. The group published the source code for the third iteration of Shai-Hulud online, launching a contest that offered a $1,000 prize in Monero (XMR) to whichever participant could compromise the highest number of downloads. Security firm Dataminr noted that the prize was a mere "participation trophy," serving as a recruitment funnel to identify high-potential hackers whose access could be purchased by the group for significantly higher sums.


Anatomy of the "Cybercats" Syndicate

Security analysts, including Austin Larsen of Google’s Threat Intelligence Group, characterize TeamPCP not as a traditional, monolithic criminal organization, but as a "peer community" of disparate actors sharing a common center of gravity.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

That center was the "Cybercats" Matrix chat server, an online hub where members collaborated, bragged about exploits, and taunted victims. The group’s inner circle included:

  • George Prepakis (@kernelstub): An exploit developer who served as a central administrator and facilitator.
  • "Boxturtle" (@xpl0itrsturtle): A notorious data broker linked to breaches at major automotive giants, including BMW, Audi, and Honda, as well as high-profile data thefts from Snapchat.
  • "SeesawSec" (Fulcrumsec): The architect behind extortion campaigns targeting industry titans like Novo Nordisk and LexisNexis.
  • "Ellis" / Ruben Thomson: The self-described leader and spokesperson, known by aliases such as "Deadcatx3" and "BulkDMT," who operated out of Cottesloe, Western Australia.
  • "pcpcasper" / Michael Gaebler: A vocal member of the Australian neo-Nazi political organization, the National Socialist Network, who was eventually identified as the second individual arrested by the AFP.

The group’s downfall was as much about their own hubris as it was about police work. Members frequently blurred the lines between their real-world identities and their online personas, using handles that appeared in their own company registrations or social media profiles.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The Undoing of Ruben Thomson: A Failure of OPSEC

The investigation into Ruben Thomson illustrates the perils of modern "doxing" and the permanence of digital breadcrumbs. Through a combination of passive DNS records, breached database analysis, and open-source intelligence (OSINT), investigators and researchers were able to link the handle "Deadcatx3" directly to Thomson.

Thomson’s mistakes were foundational. He registered corporate entities with names like "OPSEC Express," effectively using his own hacking alias in his business filings. Furthermore, his email addresses—specifically [email protected]—were linked to everything from his personal Airbnb profile to accounts on illicit hacking forums like Raidforums and Breachforums.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

In a July 2026 interview with KrebsOnSecurity conducted via Signal, a weary and remarkably candid Thomson admitted to his role in the group. He described his journey from a life of homelessness and substance abuse to the "fun" of black-hat hacking. He openly discussed his addiction to ketamine and DMT, even posting photos on Telegram of substances he was acquiring while contemplating turning himself in.


Official Responses and Legal Fallout

The Australian Federal Police have treated the case with the gravity befitting a major international threat. Following the arrests in Perth, the AFP confirmed that the two men face 14 combined charges related to cybercrime offenses.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

During the court proceedings, it was revealed that Ruben Thomson was denied bail, while Michael Gaebler’s counsel did not contest his detention. Both men are scheduled to remain in custody until their next appearance on September 18. The international cooperation required for this arrest underscores the shifting priority of law enforcement agencies to treat software supply chain attacks as a matter of national security rather than mere white-collar crime.


Implications: The New Paradigm of Supply Chain Security

The legacy of TeamPCP is not merely one of theft, but of forced evolution. Charlie Eriksen, a researcher at Aikido Security, argues that the group acted as a "stress test" for the entire software ecosystem.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The "Cooldown" Revolution

For years, the industry debated the security risks of automated package updates. TeamPCP’s relentless exploitation of these systems forced platforms like GitHub to implement a three-day "cooldown" period for Dependabot updates. This delay provides maintainers and security tools the necessary window to detect malicious injections before they are pushed to production environments.

The AI Double-Edged Sword

Eriksen notes that TeamPCP represents a new breed of threat actor—one that utilizes Large Language Models (LLMs) to bridge the gap between research and operational deployment. While traditional hacking required deep expertise in code adaptation and infrastructure management, LLMs allow less-disciplined actors to operate at a massive, high-impact scale.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

"They were noisy, they made mistakes, and they left evidence everywhere," Eriksen observed. "But they were also effective enough to humiliate Microsoft into taking supply chain security seriously."

A Warning for the Future

The TeamPCP saga serves as a sobering reminder of the fragility of the open-source supply chain. The group exploited the fundamental trust upon which the internet is built. While the arrests of Thomson and Gaebler have removed a significant threat, the ease with which a small, somewhat disorganized group of individuals managed to compromise the infrastructure of thousands of global companies suggests that the battle for software integrity has only just begun.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

As the industry moves forward, the "TeamPCP Effect" will likely be measured by a permanent shift in how code is distributed, verified, and updated. For developers and corporate security teams, the era of blind trust in upstream dependencies is officially over. The question remains whether the safeguards now being implemented will be enough to hold back the next generation of "Cybercats"—or if the tools that made TeamPCP dangerous have already been democratized to a point of no return.

Leave a Reply

Your email address will not be published. Required fields are marked *