In a landmark operation that marks the end of one of the most destructive chapters in software supply chain history, Australian Federal Police (AFP) authorities have apprehended two men in Western Australia suspected of operating as the nucleus of TeamPCP. The group, which emerged in late 2025, is blamed for an unprecedented wave of software supply chain attacks that compromised thousands of global businesses, eroded trust in open-source ecosystems, and forced a massive security overhaul at major platforms like GitHub.
The suspects, aged 21 and 23, were arrested in Perth following a joint investigation involving the AFP, the FBI, and Western Australia Police. While the authorities have maintained discretion regarding the identities of the defendants, reporting from KrebsOnSecurity and subsequent confirmation by ABC News identified the 21-year-old as Ruben Ian Thomson of Cottesloe, with the 23-year-old identified as Michael Gaebler. Both men currently remain in custody after being denied bail, awaiting a court appearance scheduled for September 18.

A Chronology of Chaos: The Rise of Shai-Hulud
TeamPCP’s trajectory onto the global stage was as swift as it was volatile. The group did not operate as a traditional, disciplined hacking collective. Instead, they functioned as an agile, chaotic amalgamation of threat actors who leveraged sophisticated automation to scale their reach.
The cornerstone of their operation was a self-propagating malicious worm dubbed "Shai-Hulud." Beginning in late 2025, the group targeted developers via phishing campaigns, hijacking credentials to access public code repositories on platforms like GitHub and NPM. Once inside, they embedded malicious code into legitimate software tools. Because these tools were foundational, the malware spread downstream to other developers’ machines, effectively creating a "cyclical exploitation" model.

- March 2026: TeamPCP executed a high-impact strike against LiteLLM, an open-source gateway connecting users to over 100 Large Language Models (LLMs). Security firm CloudSEK estimated this breach harvested cloud service keys and sensitive secrets from more than 2,500 organizations, including industry-leading technology giants.
- May 2026: The group claimed credit for compromising at least 3,800 code repositories at GitHub after a developer fell victim to a compromised code extension.
- The Contest: Perhaps the most audacious move by the group was their "supply chain hacking contest," launched in mid-2026. TeamPCP offered a $1,000 Monero (XMR) prize to participants who could conduct the largest supply chain operation using Shai-Hulud. As noted by the security firm Dataminr, this was not merely a competition but a sophisticated recruitment drive designed to acquire malicious access to popular code libraries at scale.
Anatomy of a "Cybercat" Collective
Security researchers, including those at Google’s Threat Intelligence Group, describe TeamPCP as a "peer community" rather than a hierarchical criminal organization. The group organized their communications on a Matrix chat server they dubbed "Cybercats."
This server served as a digital town square for multiple threat actors, including individuals associated with data breach brokers like "Boxturtle" (linked to the handle @xpl0itrsturtle) and "SeesawSec" (linked to the group Fulcrumsec). These members were responsible for a staggering volume of data extortion attacks, targeting high-profile entities including the BMW Group, Audi, Honda, Novo Nordisk, and LexisNexis.

The "center of gravity" for this collective was a self-described exploit developer operating under the handle @kernelstub, identified as George Prepakis. Alongside him, the group’s public-facing persona was largely managed by Ruben Thomson, who operated under various handles, including @pcpcats, EllisD25, and Deadcatx3.
The Digital Breadcrumbs: How the Leader Was Unmasked
Despite their focus on "operational security" (OPSEC)—a term they ironically used as a name for one of their shell companies—the suspects were undone by a series of glaring digital footprints.

Investigators and security researchers were able to link the various aliases to Ruben Thomson through a mosaic of leaked data and poor operational hygiene:
- Shared Infrastructure: Passive DNS records linked IP addresses used by the group to private file servers registered to the Thomson family in Perth.
- Registration Data: Email addresses like
[email protected]and[email protected], used to register cybercrime forum accounts, were directly tied to Thomson’s legitimate business ventures and social media profiles. - The "Deadcatx3" Fail: In one of the most critical lapses, the HackerOne bug bounty profile for "Ruben Thomson" utilized the handle Deadcatx3, which multiple security firms had already flagged as a primary alias for the TeamPCP leadership.
Thomson’s personal history, including his background in South Africa and his subsequent move to Australia, provided further corroboration for the intelligence gathered by firms like Intel 471 and Flashpoint, which had tracked the group’s activity to South African IP ranges.

The Human Element: An Interview with "Ellis"
In early July 2026, KrebsOnSecurity conducted an interview with the individual known as "Ellis" (Thomson) via the encrypted messaging app Signal. The conversation revealed a portrait of a young man struggling with substance abuse and a sense of isolation.
Ellis admitted that he had been "blackhatting" as a distraction from his personal life and a means to earn a living when legitimate employment seemed out of reach. "Blackhatting is fun," he told the interviewer. "There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out."

He claimed that he had ceased his direct involvement with TeamPCP by March 2026, following a period of sobriety, but his messages in the Cybercats Matrix chat suggested a continued, turbulent relationship with hallucinogens and dissociative substances. His resignation to the possibility of arrest proved prophetic, as he noted, "If I’ve already been found out then it’s out of my control, I’ll make peace with that."
Implications: A New Era of Supply Chain Security
The legacy of TeamPCP is a paradox: while they caused widespread damage, their actions catalyzed a long-overdue paradigm shift in cybersecurity.

Charlie Eriksen, a security researcher at Aikido Security, argues that TeamPCP represents a new breed of threat actor—one that exists in the gray space between ideology, profit, and simple disruption. "They managed to wake up Microsoft to the fact that they had become negligent," Eriksen noted. "By compromising GitHub and stealing their source code, they humiliated Microsoft into action."
The immediate industry response has been significant. Following the Shai-Hulud campaigns, GitHub implemented a "three-day cooldown" mechanism for Dependabot, a feature designed to prevent the automatic ingestion of compromised software updates. This measure, now being adopted across various programming ecosystems, acts as a critical buffer for developers to verify the integrity of their dependencies.

Official Responses and Conclusion
The Australian Federal Police have hailed the arrests as a critical disruption of a sophisticated global threat. The charges against the two men—a combined total of 14 cybercrime offenses—reflect the gravity of their actions in compromising the foundational layers of the internet.
As the legal proceedings against Thomson and Gaebler move forward, the cybersecurity community is left to grapple with the reality that tools like AI and Large Language Models are lowering the barrier to entry for malicious actors. "They can be noisy, they can make mistakes," Eriksen observed. "But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous."

TeamPCP’s rapid rise and fall serves as a sobering case study in modern threat intelligence. It underscores that while automated, AI-assisted hacking can scale threats to unprecedented levels, the human element—the ego, the addiction, and the failure to maintain true digital anonymity—remains the ultimate point of vulnerability for even the most "prolific" criminal syndicates.
