Anatomy of a Software Supply Chain Takedown: Inside the Australian Arrests of TeamPCP Core Operatives

By Global Cybersecurity & Intelligence Desk
Published Following Joint Operations by the AFP, FBI, and WAPF


Main Facts

In a coordinated international sweep that deals a massive blow to the global underground economy, Australian authorities have arrested two men from Western Australia believed to be the primary architects behind TeamPCP.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Regarded by threat intelligence analysts as one of the most prolific and disruptive cybercrime syndicates in recent memory, TeamPCP is credited with executing the longest-running software supply chain attack spree in history. The syndicate wreaked havoc across global cloud ecosystems, open-source repositories, and artificial intelligence infrastructures by embedding malicious code into widely trusted software packages.

According to an official media release by the Australian Federal Police (AFP), a joint operation involving the AFP, the Federal Bureau of Investigation (FBI), and the Western Australia Police Force (WAPF) culminated in the dawn raids and subsequent arrests of two men, aged 21 and 23, in Perth. The suspects face a combined total of 14 cybercrime offenses.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

While law enforcement initially withheld the identities of the accused, investigative reporting by KrebsOnSecurity and subsequent updates from the Australian Broadcasting Corporation (ABC News) confirmed that the 21-year-old suspect is Ruben Ian Thomson of Cottesloe—known widely across cybercrime forums by monikers such as EllisD25, BulkDMT, and Express. The second suspect, a 23-year-old man identified as Michael Gaebler, was also taken into custody. Both appeared before the Perth Magistrates Court, where Thomson was formally denied bail.

TeamPCP’s reign of terror upended the foundational trust models of open-source software. By weaponizing compromised developer credentials on public repositories like GitHub and npm, the group deployed a self-propagating worm dubbed Shai-Hulud. This malicious code harvested sensitive cloud service keys, enterprise credentials, and internal proprietary codebases from thousands of global organizations, leaving a trail of multimillion-dollar extortions and operational chaos in its wake.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Chronology of an Escalation

The trajectory of TeamPCP from an obscure collective of freelance exploit developers into a global menace spans roughly nine months of intense, highly destructive cyber activity.

  • Late 2025: TeamPCP bursts onto the cybercrime landscape. Leveraging phishing campaigns and credential theft, the group compromises public code repositories on GitHub and npm. They introduce the Shai-Hulud self-propagating worm, which infects developer machines and automatically replicates malicious code into downstream projects.
  • September 2025: Syndicate leader Ruben Thomson (operating as BulkDMT and EllisD25) begins peddling stolen access and infrastructure services on forums like DarkForums and Breachstars, utilizing virtual private server hosting setups known as "DMT Host."
  • March 2026: In one of their most audacious operations, TeamPCP targets AI infrastructure by compromising LiteLLM, an open-source AI gateway connecting users to over 100 large language models (LLMs). The breach harvests cloud service keys from more than 2,500 corporations, including prominent global technology firms.
  • May 2026: TeamPCP claims responsibility for compromising at least 3,800 code repositories on Microsoft-owned GitHub after a developer installs a malicious code extension. Concurrently, the group releases the source code for Shai-Hulud 3.0 and launches a public hacking contest on Telegram. Offering a $1,000 Monero baseline prize, the contest incentivizes external actors to use the worm to compromise high-download open-source libraries as a novel recruitment mechanism.
  • June 2026: Cybersecurity researchers, including those at Google, trace TeamPCP’s residential internet traffic to South Africa and Western Australia. Investigators begin unspooling operational security (OpSec) failures, tying forum handles directly to real-world entities in Perth.
  • Early July 2026: Investigative journalists establish contact with Ruben Thomson via encrypted messaging apps. Thomson candidly discusses his motivations, drug struggles, and eventual decision to step back from active leadership in March 2026.
  • Late July 2026: Following intense industry pressure generated by TeamPCP’s attacks—specifically the GitHub compromise—Microsoft introduces a mandatory three-day "cooldown" period for Dependabot to mitigate supply chain injection risks.
  • Late August 2026: Joint law enforcement operations by the AFP, FBI, and WAPF execute simultaneous raids in Western Australia, arresting Thomson and Gaebler. Both men are remanded in custody ahead of their next court appearance.

Supporting Data & Operational Mechanics

Unlike structured, hierarchical ransomware cartels or state-sponsored advanced persistent threat (APT) groups, security analysts describe TeamPCP as a loose federation or peer community of skilled individual threat actors. Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group, noted that the collective operated with a distinct "center of gravity" anchored by elite exploit developers and data brokers.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The "Cybercats" Ecosystem

The group utilized a Matrix chat server dubbed "Cybercats" for daily coordination. Administrators and members included figures using aliases tied to high-profile extortion and leak operations:

  • Boxturtle (@xpl0itrs): A data breach broker active on Breachforums and Darkforums, linked to massive data thefts from automotive giants including BMW, Audi, Honda, Mercedes-Benz, Volvo, and Toyota.
  • SeesawSec: The alias representing Fulcrumsec, a cybercrime outfit responsible for extortion campaigns against pharmaceutical titan Novo Nordisk, data broker LexisNexis, and Fortune 500 electronics distributor Avnet.
  • @pcpcasper: Identified as Michael Gaebler, an active member of the Australian neo-Nazi group National Socialist Network, whose digital footprint and shared media eventually helped tie him to Western Australia.

The OpSec Failures

Despite their technical sophistication in software exploitation, TeamPCP’s leadership suffered from catastrophic operational security errors. According to intelligence compiled by SpyCloud, Intel 471, and Flashpoint, Ruben Thomson repeatedly reused email addresses ([email protected], [email protected]), passwords (joshuathomson1), and physical IP addresses across multiple years.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Most critically, Thomson registered an account on HackerOne—the prominent bug bounty platform—using the handle Deadcatx3, an alias heavily documented by security firms as a primary TeamPCP identifier. Furthermore, Thomson incorporated local Australian entities under names like OPSEC Express and Tensor Industries, directly mocking the security concept of operational compartmentalization.


Official Responses

The dismantling of TeamPCP’s core cell has drawn widespread commentary from international law enforcement and private sector cybersecurity leaders.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

In their official joint statement, the Australian Federal Police emphasized that the arrests underscore the borderless nature of modern cybercrime and the effectiveness of cross-border intelligence sharing.

"This sophisticated cybercrime syndicate allegedly created malicious open-source software to rob thousands of global businesses," the AFP stated, highlighting the complex digital forensics required to map the suspects’ real-world locations.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Charlie Eriksen, a security researcher at Aikido Security, pointed out that TeamPCP represents a dangerous evolution in the threat landscape. Because actors can leverage Large Language Models (LLMs) to bridge the gap between complex research and operational execution, groups can achieve massive scale without the discipline traditionally required by professional criminal syndicates.

"They can be noisy, they can make mistakes, and they can leave evidence everywhere," Eriksen observed. "They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it makes them more dangerous."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Implications for the Global Software Supply Chain

While the human cost of the arrests involves lengthy custodial sentences for young, drug-addicted hackers trading short-term digital thrills for federal indictments, TeamPCP’s institutional legacy will permanently alter how software is written, distributed, and maintained.

Security analysts widely agree that the Shai-Hulud campaign served as the ultimate stress test for modern software development life cycles (SDLC). For years, security advocates urged code repositories to implement stricter safeguards against automated dependency injection. TeamPCP’s relentless exploitation forced the industry’s hand.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Following the LiteLLM and GitHub compromises, platforms like GitHub enacted sweeping policy changes, most notably the implementation of a mandatory three-day "cooldown" period for Dependabot package updates. This grace period allows automated scanners and package maintainers vital breathing room to catch poisoned code libraries before they propagate into enterprise production environments. Similar safeguards have been rapidly adopted across Python and JavaScript ecosystems.

Ultimately, as Charlie Eriksen aptly summarized: TeamPCP achieved in the span of a few months what the supply chain security community had been lobbying for over the course of a decade. By ruthlessly exposing the fragile trust model of open-source software, they humiliated major tech conglomerates into tightening their defenses—even if the price of that lesson was paid by thousands of breached global corporations and, ultimately, the freedom of the cybercats themselves.