September 13, 2026

Operation "Cybercats": Inside the Downfall of TeamPCP, the Notorious Open-Source Supply Chain Extortion Syndicate

operation-cybercats-inside-the-downfall-of-teampcp-the-notorious-open-source-supply-chain-extortion-syndicate

operation-cybercats-inside-the-downfall-of-teampcp-the-notorious-open-source-supply-chain-extortion-syndicate

By Global Security Desk

Authorities in Australia have apprehended two men believed to be the core figures behind TeamPCP, a prolific and destructive cybercrime syndicate. The group is held responsible for orchestrating the longest-running and most pervasive software supply chain attack campaign in digital history, compromising thousands of corporate entities, major automotive manufacturers, and critical artificial intelligence (AI) infrastructure worldwide.

In a joint statement released by the Australian Federal Police (AFP) alongside the Federal Bureau of Investigation (FBI) and the Western Australian Police Force (WAPF), law enforcement confirmed the arrests of two Western Australian men, aged 21 and 23. The suspects were captured during early morning raids following an international probe into a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

While the AFP initially withheld the identities of the defendants, investigative reporting and subsequent local news confirmations identified the 21-year-old suspect as Ruben Ian Thomson of Cottesloe, Western Australia—widely known online as the primary TeamPCP leader—and the 23-year-old suspect as Michael Gaebler, alleged to be the high-profile Telegram participant known as @pcpcasper.


Chronology of a Campaign: The Rise and Fall of TeamPCP

TeamPCP burst onto the cybercriminal underworld in late 2025, rapidly evolving from an ad-hoc collective of malicious developers into a structured engine of data extortion and ecosystem compromise. Rather than utilizing traditional ransomware deployed via phishing emails, TeamPCP perfected the art of open-source poisoning.

The Shai-Hulud Worm and Cyclical Exploitation

The group’s most notable weapon was a self-propagating worm dubbed Shai-Hulud. TeamPCP members systematically targeted open-source software maintainers, stealing or phishing credentials at public code repositories like GitHub and NPM. Once inside, they injected malicious payloads into legitimate code libraries.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Journalist Andy Greenberg, writing for Wired, detailed the core mechanics of TeamPCP’s cyclical strategy:

"The hackers gain access to a network where an open source tool commonly used by coders is being developed. The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows."

By May 2026, the syndicate released the source code for the third iteration of Shai-Hulud and launched an open cybercrime contest. Offering a baseline prize of $1,000 in Monero (XMR) cryptocurrency, TeamPCP scored participants based on the download volume of the packages they compromised. Security firm Dataminr noted that the nominal prize acted merely as a "participation trophy," with the true intent being talent identification and malicious access acquisition at massive scale.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

High-Profile Breaches: AI Gateways and Global Giants

TeamPCP’s operations quickly scaled beyond routine developer targeting into high-value corporate environments:

  • March 2026 (LiteLLM Attack): The group compromised LiteLLM, an open-source AI gateway connecting users to over 100 large language models. Security firm CloudSEK discovered that this single attack harvested cloud service keys and infrastructure secrets from more than 2,500 organizations, including elite global technology companies.
  • May 2026 (GitHub Compromise): TeamPCP claimed responsibility for breaching at least 3,800 code repositories at the Microsoft-owned GitHub after a developer installed a compromised browser extension.
  • The "Cybercats" Extortion Wave: Associated actors operating within the "Cybercats" chat ecosystem—including data brokers using handles like @xpl0itrsturtle and SeesawSec (linked to Fulcrumsec)—began peddling stolen data from automotive giants (BMW Group, Audi, Honda, Mercedes-Benz, Volvo, and Toyota), pharmaceutical titan Novo Nordisk, data broker LexisNexis, and Fortune 500 electronics distributor Avnet.

Supporting Data and Technical Profiling: Exposing "Ellis"

Security intelligence firms—including Intel 471, Flashpoint, SpyCloud, and Google Threat Intelligence Group—spent months mapping the digital footprints left by TeamPCP’s leadership, specifically an individual operating under aliases such as EllisD25/LSD, BulkDMT, Express, and Deadcatx3.

The "Cybercats" Center of Gravity

Security experts emphasized that TeamPCP was less a monolithic gang than an interconnected peer community. Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group, noted: "It is not a structured criminal crew with a single operator. It is a peer community of individually-skilled actors, with one clear center of gravity."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

That center of gravity orbited around technical forums, Matrix servers dubbed "Cybercats," and cryptographic messaging channels. However, a series of compounding operational security (OPSEC) failures unraveled the anonymity of the group’s leader, Ruben Thomson.

The Paper Trail of Operational Security Failures

  1. Email and Forum History: Threat intelligence tracking revealed that the email address [email protected] was tied to the account Express on Breachforums, which advertised stolen data from the South African State Information Technology Agency. SpyCloud traced the same email address to a 2022 Raidforums account (ChristmasSnow) accessed primarily via Perth Internet Service Providers.
  2. Passive DNS and Family Records: Passive DNS analysis by DomainTools linked Perth IP addresses used by the suspects to private file servers managed by the Thomson family. Open-source intelligence platforms (Epieos and Constella Intelligence) tied these addresses and alternate emails (such as [email protected]) to Ruben Thomson, his brother Ruben, and his dentist father, Ian Thomson.
  3. The Upwork and Airbnb Confessions: Ruben Thomson maintained an Upwork freelance profile and an Airbnb account where he explicitly used his nickname, Ellis, describing himself as a Perth-based full-stack PHP developer familiar with Linux, SQL, and Python script automation for social media bots.
  4. The HackerOne Blunder: In June 2025, Ruben Thomson registered on the bug bounty platform HackerOne under the username Deadcatx3—a handle that multiple cybersecurity firms had already cataloged as an alias directly tied to TeamPCP leadership.
  5. Corporate Registration Irony: Australian Business Register records showed Ruben Thomson incorporated entities including Secure Computing Solutions, Tensor Industries, and OPSEC Express. Using parts of his own cybercrime monikers for corporate registration represented a complete abandonment of functional operational security.

Official Responses and Law Enforcement Action

The coordinated takedown was executed on Wednesday morning by the Australian Federal Police, the FBI, and state authorities.

According to reports from ABC News, Ruben Ian Thomson and Michael Gaebler appeared before the Perth Magistrates Court. Thomson was formally denied bail, while Gaebler’s defense attorney did not seek bail during the initial hearing. Both men are remanded in custody until their next scheduled court appearance on September 18. They face a combined total of 14 cybercrime charges.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Security researchers have praised the cross-border law enforcement cooperation. However, industry experts emphasize that the syndicate’s legacy extends far beyond a courtroom.


Industry Implications and the New Threat Landscape

TeamPCP’s reign has permanently altered the calculus of software supply chain security. According to Charlie Eriksen, a security researcher at Aikido Security, TeamPCP represents an entirely new breed of threat actor:

"They are not a state actor, not quite organized cybercrime, and not purely ideological. Their motivations seem to mix money, disruption, attention, and ideology."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The AI Knowledge Gap Compression

Eriksen noted that historically, a wide technical gulf existed between reading about an exploit technique and operationalizing it at scale. However, the proliferation of Large Language Models (LLMs) and generative artificial intelligence has compressed that gap. Threat actors can now scale operations rapidly without necessarily mastering the deep operational discipline traditionally required by professional criminal syndicates.

"They can be noisy, they can make mistakes," Eriksen observed. "They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous."

A Catalyst for Positive Ecosystem Reform

Ironically, security analysts argue that TeamPCP’s destructive campaigns served as a much-needed shock to the software industry. By weaponizing trusted ecosystems like GitHub and NPM through the Shai-Hulud worm, the group successfully humiliated major tech platforms into upgrading their security posture.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

In direct response to TeamPCP’s activities, Microsoft’s GitHub introduced a mandatory three-day "cooldown" period for Dependabot updates in late July, allowing security researchers and package maintainers critical windows to catch malicious code insertions before automated dependencies pull them into corporate environments. Similar cooldown mechanisms have since been adopted across Python and JavaScript ecosystems.

As Eriksen concluded: "TeamPCP achieved in the span of a few months what the supply chain security community has been unable to do for years. They managed to wake up Microsoft to the fact that they had become negligent in terms of security."