In a major blow to international cybercrime, the Australian Federal Police (AFP) have arrested two men from Western Australia, aged 21 and 23, in connection with the operations of "TeamPCP"—a prolific and chaotic threat group responsible for what experts characterize as the longest-running software supply chain attack spree in history. The arrests, carried out with the assistance of the FBI and the Western Australia Police Force, mark a pivotal moment in the fight against a new generation of digital extortionists who have weaponized open-source ecosystems to compromise thousands of global businesses.
While the AFP has withheld the identities of the suspects, independent investigative reporting by KrebsOnSecurity has linked the group’s operations to a young developer in the beachside Perth suburb of Cottesloe. The investigation reveals a startling lack of operational security (OPSEC) that eventually led to the undoing of a group that had, until recently, seemed untouchable.

The Rise of the "Shai-Hulud" Menace
TeamPCP emerged onto the global stage in late 2025, distinguishing itself not through traditional phishing or ransomware, but through the large-scale, automated poisoning of open-source software supply chains. Their primary tool, a self-propagating worm dubbed "Shai-Hulud," allowed the group to inject malicious code into hundreds of development tools.
The strategy was chillingly cyclical. By compromising the environment of an open-source tool, TeamPCP would wait for unsuspecting developers to download the "updated" package. Once the malware landed on a developer’s machine, it would scrape credentials for public repositories like GitHub or NPM. These stolen credentials would then be used to publish further malicious versions of other tools, creating a self-sustaining feedback loop of infections.

Journalist Andy Greenberg, writing for Wired, aptly described this as a "cyclical exploitation of software developers." By targeting the very tools used to build software, TeamPCP managed to penetrate the perimeter of thousands of corporate cloud environments, including those of several Fortune 500 companies.
Chronology of a Digital Rampage
The impact of TeamPCP’s campaign was felt across the tech industry throughout 2025 and 2026:

- Mid-2025: TeamPCP establishes its presence, utilizing forums to sell stolen access and peddling their own virtual private server (VPS) services, such as "DMT Host."
- September 2025: The group begins advertising access to massive datasets, including 14 gigabytes stolen from South Africa’s State Information Technology Agency.
- March 2026: TeamPCP executes a high-profile attack on "LiteLLM," an open-source AI gateway. Security firm CloudSEK later estimated this single breach harvested cloud service keys from over 2,500 organizations.
- May 2026: The group claims responsibility for compromising 3,800 code repositories on GitHub after a single developer installed a compromised extension.
- June 2026: Investigations by cybersecurity firms and journalists begin to converge on a central figure in Western Australia.
- August 2026: Following months of monitoring and intelligence gathering, the AFP conducts raids in Western Australia, taking the suspects into custody.
The "Cybercats" and the Anatomy of the Group
Security analysts, including Austin Larsen of Google Threat Intelligence, have noted that TeamPCP is not a traditional, hierarchical criminal organization. Instead, it is an amalgamation of threat actors—a "peer community" that occasionally collaborates under the banner of a Matrix chat server named "Cybercats."
The server functioned as a hub for various groups to share exploits and taunt victims. Administrators, including handles like "Boxturtle" (associated with data broker "xpl0itrs") and "SeesawSec" (linked to the Fulcrumsec group), used these channels to coordinate attacks on automotive giants, including BMW, Audi, and Honda, as well as major entities like LexisNexis and Novo Nordisk.

The group’s internal culture was marked by a bizarre mix of neo-Nazi ideology and intense, self-destructive behavior. One of the central figures, known by the handle "@pcpcasper," was found to be a vocal member of Australia’s National Socialist Network. The group’s leader, who operated under various aliases including "Ellis," "BulkDMT," and "Deadcatx3," frequently discussed his struggles with addiction to methamphetamine and other substances in open chat channels, often blaming his absence from operations on his substance use.
The Trail of Evidence: A Failure of OPSEC
The undoing of TeamPCP was not the result of a single brilliant hack by law enforcement, but rather the culmination of a systematic failure by the perpetrators to mask their real-world identities.

Tracing the digital footprints of the leader—identified through research as Ruben Thomson—reveals a trail of carelessness. Thomson used the same email addresses (such as [email protected]) to register both legitimate business entities in Australia and notorious cybercrime forum accounts. Records from DomainTools and Constella Intelligence linked IP addresses in Perth to file servers and corporate accounts under the Thomson name.
In an act of supreme irony, the suspect registered several businesses in Australia, including one named "OPSEC Express"—a direct nod to his own alias and a mocking, albeit unintended, commentary on his complete lack of operational security. Furthermore, his profile on the bug-bounty platform HackerOne used the handle "Deadcatx3," which security researchers had already publicly identified as an alias linked to TeamPCP.

An Interview with "Ellis"
In a candid and chilling interview with KrebsOnSecurity conducted via the encrypted messaging app Signal shortly before his arrest, the individual known as "Ellis" spoke about his journey into the dark side of the internet.
"Blackhatting is fun," Ellis admitted. "There are actual rewards and incentives to learn, and you grow with your team. Without qualifications, no employer will even take the time to hear you out."

He claimed his involvement was never about the money—which he estimated at a modest $20,000—but about finding a place where his skills were recognized. His outlook on his future was grimly resigned: "If I’ve already been found out, then it’s out of my control; I’ll make peace with that." He expressed a desire for professional guidance that he felt society had failed to provide, yet he showed no remorse for the thousands of businesses he disrupted.
Official Response and Legal Implications
The AFP’s statement confirmed that the two men face a combined 14 cybercrime offenses. While the legal process in the Perth Magistrates Court will likely be lengthy, the implications of these arrests extend far beyond the courtroom.

The government’s intervention serves as a warning that even the most "sophisticated" cyber-syndicates are vulnerable to the traditional investigative techniques of law enforcement. By connecting digital aliases to physical locations and corporate registrations, the AFP demonstrated that "anonymous" online actors remain subject to the laws of the physical world.
The Lasting Legacy: A Wake-up Call for Tech Giants
Perhaps the most significant consequence of TeamPCP’s reign is the radical shift it forced in software security policies. Charlie Eriksen, a security researcher at Aikido Security, argues that TeamPCP acted as a "forced catalyst" for the industry.

"They managed to wake up Microsoft to the fact that they had become negligent," Eriksen noted. "By compromising GitHub and stealing their source code, they humiliated Microsoft into action."
In response to the Shai-Hulud attacks, major platforms like GitHub have implemented a "three-day cooldown" mechanism for dependencies. This buffer period is designed to prevent the rapid, automated propagation of malicious updates, giving security teams the necessary time to detect and quarantine compromised packages.

Eriksen suggests that while TeamPCP was dangerous due to its volatility and lack of professional discipline, it ultimately did the industry a favor. "They achieved in the span of a few months what the supply chain security community has been unable to do for years."
As the dust settles, the arrest of these two men marks the end of an era of unprecedented supply chain vulnerability. However, the rise of LLM-assisted cybercrime remains a growing concern. As Eriksen warned, the "knowledge gap" that once kept hackers from executing high-level attacks is closing, meaning the next iteration of "TeamPCP" may not be so careless with their identity—or so easily stopped.
