Australian Federal Police Arrest Alleged Masterminds Behind Notorious TeamPCP Cybercrime Syndicate

Law enforcement authorities in Australia, working in a coordinated international operation alongside the Federal Bureau of Investigation (FBI) and local Western Australian police, have arrested two men suspected of operating TeamPCP, a prolific cybercrime and data extortion ring. The syndicate is widely considered responsible for orchestrating the longest-running and most damaging software supply chain attack campaign in internet history.
The Australian Federal Police (AFP) disclosed in an official media release that the suspects—two residents of Western Australia aged 21 and 23—were taken into custody following raids in Perth. The men are accused of running a highly sophisticated cybercriminal enterprise that engineered malicious open-source software packages designed to compromise corporate environments, harvest cloud service credentials, and extort thousands of global business entities. While the AFP withheld the names of the defendants during initial announcements, local court filings and investigative journalism later confirmed the 21-year-old suspect is Ruben Ian Thomson, operating under aliases such as "Ellis," while the 23-year-old was identified as Michael Gaebler. Both face a combined total of 14 serious cybercrime offenses.

The Anatomy of a Supply Chain Threat
TeamPCP first emerged on the global cybercrime landscape in late 2025, quickly distinguishing itself through an innovative and relentless strategy: embedding malicious code directly into widely utilized open-source software libraries. Unlike traditional ransomware gangs that breach perimeters via phishing or compromised RDP ports, TeamPCP leveraged a cyclical exploitation model.
According to security analysts from firms like Google Threat Intelligence Group and CloudSEK, the group gained initial access to developer networks where foundational open-source tools were maintained. By compromising developer accounts on public code repositories such as GitHub and NPM—frequently via advanced credential harvesting—they injected malware payloads into the source code.

When unsuspecting software developers downloaded these routine updates, the malware propagated to their local machines. If those developers happened to be working on other software tools destined for commercial use, the malicious payload was bundled into those secondary applications as well. This self-propagating worm, famously dubbed "Shai-Hulud," created an expanding cascade of compromised networks, touching thousands of corporate pipelines and AI infrastructure gateways.
A Chronology of Escalation: From Open-Source Compromise to AI Exploitation
The scope and scale of TeamPCP’s operations expanded rapidly throughout late 2025 and mid-2026, marking a significant evolution in software supply chain vulnerabilities:

- Late 2025: TeamPCP bursts onto the scene, launching the Shai-Hulud worm and embedding payloads in hundreds of open-source software tools on GitHub and NPM.
- September 2025: Leaders of the syndicate actively market virtual private server hosting (DMT Host) and trade data leaks on English-language cybercrime forums like DarkForums and Breachstars.
- March 2026: TeamPCP executes a high-profile attack against LiteLLM, an open-source AI gateway linking users to over 100 large language models. The breach harvests API keys, cloud service credentials, and internal secrets from more than 2,500 organizations, including major technology enterprises.
- May 2026: The group claims responsibility for compromising at least 3,800 code repositories on Microsoft-owned GitHub after an engineer installs a malicious code extension. Simultaneously, the source code for Shai-Hulud 3.0 is published, accompanied by a notorious hacking contest offering Monero (XMR) cryptocurrency prizes to incentivize participants to compromise popular software libraries.
- June 2026: Security researchers and intelligence firms, including SpyCloud, Intel 471, and independent journalist Brian Krebs, map out the digital footprints, infrastructure, and real-world identities linked to the syndicate’s core leadership.
- August 2026: The AFP, in coordination with the FBI, executes arrest warrants in Western Australia, taking Thomson and Gaebler into custody.
The "Cybercats" Collective and Operational Security Failures
Security experts emphasize that TeamPCP was not structured as a traditional, hierarchical criminal enterprise with a single centralized commander. Instead, it operated as a loose, peer-driven coalition of sophisticated threat actors drawn from various underground gangs. These actors communicated daily via a Matrix chat server dubbed "Cybercats," an infrastructure hub established by prominent exploit developer George Prepakis, known online as @kernelstub.
The Cybercats community served as a collaborative war room where members frequently bragged about intrusions, coordinated data extortion campaigns, and taunted corporate victims publicly via social media platform X (formerly Twitter) before mainstream media outlets could report the incidents. Prominent handles within the server included "Boxturtle" (linked to data breach broker operations selling stolen archives from global automotive giants like BMW, Audi, Honda, and Toyota) and "SeesawSec" (associated with Fulcrumsec, a gang tied to attacks on pharmaceutical giant Novo Nordisk and Fortune 500 distributor Avnet).

Despite their technical prowess in exploiting global software supply chains, the core leadership of TeamPCP suffered from catastrophic operational security (OPSEC) failures. Investigators were able to map the true identity of Ruben Thomson through a trail of digital breadcrumbs left over several years. Thomson reused passwords across historical cybercrime forums like Raidforums and Altenen, registered infrastructure using personal email addresses tied to his family in Perth, and even registered a HackerOne bug bounty profile under the alias "Deadcatx3"—a handle independently flagged by cybersecurity researchers as a primary identifier for TeamPCP.
Furthermore, public business registrations in Australia revealed that Thomson had incorporated corporate entities with names directly mocking operational security principles, such as "OPSEC Express," while utilizing communication handles associated with his dark web personas.
Interviews and Personal Struggles Behind the Keyboard

In interviews conducted prior to his arrest, Thomson—who communicated under various pseudonyms including EllisD25, BulkDMT, and Express—was remarkably candid about his motivations, background, and personal struggles. Describing a life complicated by long-standing battles with substance abuse, homelessness, and addiction to narcotics such as methamphetamine and synthetic psychedelics, Thomson noted that cybercrime provided both intellectual stimulation and a means of survival.
"Blackhatting is fun," Thomson stated in an interview with security journalist Brian Krebs, noting that the underground ecosystem offered real incentives to learn complex engineering skills that traditional academic and employment pathways failed to recognize. He claimed to have earned approximately $20,000 through his activities with TeamPCP, asserting that fame and fortune were secondary to the camaraderie and intellectual engagement found within malware development communities.
Despite expressions of remorse regarding his addiction and a stated desire to eventually leave the criminal underworld behind, Thomson’s operational habits remained erratic. Federal investigators monitored his communications as he openly discussed struggles with sobriety, substance consumption, and plans to tie up loose ends just days before law enforcement closed in.

Industry Implications and the Push for Defensive Safeguards
The disruption of TeamPCP has been widely praised by cybersecurity professionals, who view the syndicate’s reign as a watershed moment for software supply chain security. Charlie Eriksen, a security researcher at Aikido Security, noted that TeamPCP represents a dangerous new breed of threat actors who defy traditional categorization—neither state-sponsored nor strictly financially motivated, but driven by a volatile mix of disruption, ideology, and technical curiosity.
Eriksen pointed out that the proliferation of artificial intelligence and large language models has significantly compressed the technical learning curve, allowing threat actors with limited formal operational discipline to execute campaigns of unprecedented scale. However, this exact noisiness and disregard for standard security protocols ultimately exposed the group to international law enforcement agencies.

The legacy of TeamPCP may ultimately be the forced modernization of software ecosystem defenses. In direct response to the widespread dissemination of the Shai-Hulud worm, major platforms instituted sweeping defensive changes. In late July, Microsoft-owned GitHub introduced a mandatory three-day "cooldown" period for Dependabot updates, designed to give security tools and package maintainers critical windows of time to identify and quarantine poisoned software versions before they are automatically integrated into production codebases. Similar cooldown mechanisms have since been adopted across Python and JavaScript packaging ecosystems.
Security analysts emphasize that while the arrest of Thomson and Gaebler deals a severe blow to TeamPCP, the structural vulnerabilities within open-source software supply chains remain a persistent global challenge. Both defendants appeared before the Perth Magistrates Court following their arrests and were remanded into custody without bail, with their next court appearance scheduled for September 18.







