The Australian Federal Police (AFP) have successfully concluded a high-stakes investigation into the notorious cybercrime collective known as TeamPCP, announcing the arrest of two Western Australian men, aged 21 and 23, in connection with what officials describe as the most persistent and damaging software supply chain attack spree in recent history. The suspects, identified in subsequent court filings as Ruben Ian Thomson and Michael Gaebler, were apprehended in Perth following a joint operation involving the AFP, the FBI, and Western Australia Police. The pair face a combined 14 charges related to the creation and distribution of malicious open-source software, a campaign that reportedly compromised thousands of corporate environments and global business networks.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The arrests mark a significant pivot point in the global fight against "poisoned-pipeline" attacks. By embedding malicious code directly into widely used open-source libraries, TeamPCP was able to bypass traditional perimeter defenses, effectively turning the trust inherent in software development ecosystems against the organizations that rely on them. The operation that led to the duo’s capture was, in part, the result of a long-term digital footprint analysis, with investigators successfully linking the suspects to a trail of breadcrumbs—including social media accounts, domain registrations, and public forum posts—that were left behind despite the group’s attempts to maintain operational security.

A Chronology of Chaos: The Rise of Shai-Hulud

TeamPCP emerged onto the global cybercrime landscape in late 2025, rapidly distinguishing themselves from traditional ransomware gangs. Instead of merely encrypting data for extortion, the group prioritized the systemic corruption of the software supply chain. Their primary weapon was a self-propagating worm dubbed "Shai-Hulud," which targeted the credentials of developers at major repositories like GitHub and NPM.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

By compromising these accounts, the group could inject backdoors into legitimate software packages. Because these packages were trusted by developers, the malicious code would be automatically pulled into downstream applications, creating a cascading effect.

The group’s operational timeline reveals a rapid escalation in ambition:

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
  • Late 2025: TeamPCP begins its operations, focusing on small-scale credential harvesting and initial experimentation with malicious code injection.
  • Early 2026: The group introduces the Shai-Hulud 3.0 iteration, accompanied by a perverse "recruiting contest" that offered $1,000 in Monero to hackers who could compromise the most popular code libraries.
  • March 2026: The group executes its most significant attack to date, targeting the LiteLLM open-source AI gateway. Security firm CloudSEK estimated this single breach compromised cloud service keys belonging to over 2,500 organizations, including major global technology firms.
  • May 2026: TeamPCP claims credit for infiltrating over 3,800 code repositories on GitHub after a developer inadvertently installed a compromised extension.
  • July 2026: Investigative journalists and security researchers begin piecing together the identities of the group’s leadership, noting a direct link between the "Deadcatx3" alias and the Australian-based Ruben Thomson.
  • August 2026: The AFP executes search warrants in Perth, leading to the arrest of Thomson and Gaebler.

The Anatomy of the Cybercats Network

Security researchers, including those at Google Threat Intelligence and various independent firms, have described TeamPCP not as a singular hierarchical organization, but as a "center of gravity" for a loose confederation of threat actors. This network, which utilized a Matrix chat server dubbed "Cybercats," served as a nexus for disparate criminal groups to share stolen data, trade exploits, and coordinate attacks.

The investigation into "Cybercats" revealed that the group’s leadership was surprisingly cavalier regarding their real-world identities. The lead administrator, operating under the alias "Kernelstub" (later identified as Ruben Thomson), was linked to a series of business entities in Australia with names that ironically referenced his own cybercrime handles, such as "OPSEC Express."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Furthermore, the group’s internal communications were often punctuated by discussions of substance abuse and, in some cases, ideological radicalization. Evidence suggests that Michael Gaebler, the 23-year-old suspect, maintained active links to the National Socialist Network in Australia, highlighting a complex and often unpredictable intersection between technical cyber-espionage and extremist ideology.

Data and Impact: The Cost of the Breach

The economic impact of TeamPCP’s activities remains difficult to quantify precisely, but the scope of their reach was unprecedented. By compromising the AI supply chain via LiteLLM, the group gained access to the infrastructure of Fortune 500 companies, pharmaceutical giants like Novo Nordisk, and major automotive manufacturers including Audi, Honda, and Mercedes-Benz.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The scale of the "poisoned-pipeline" is evidenced by the sheer number of affected code repositories. Unlike traditional data breaches, which involve the theft of static records, TeamPCP’s attacks involved the injection of dynamic, malicious code into the development cycle. This meant that the security of millions of users was compromised through the software they trusted for their daily operations.

"They were noisy, they took risks, and they operated with a level of disregard for professional criminal standards that would have been rejected by established syndicates," noted Charlie Eriksen, a security researcher at Aikido Security. "However, their very recklessness was their power. They forced the hand of organizations like Microsoft to implement necessary, long-overdue security updates."

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

Official Response and Legal Proceedings

The Australian Federal Police statement emphasized the sophisticated nature of the investigation. By working in tandem with the FBI, the AFP was able to correlate international IP logs with local ISP data in Western Australia, ultimately piercing the veil of anonymity the suspects attempted to construct using VPNs and encrypted messaging platforms.

In the Perth Magistrates Court, prosecutors have been clear regarding the severity of the charges. Ruben Thomson was denied bail, reflecting the court’s concern regarding the potential for further digital interference and the risk of flight. Michael Gaebler’s legal counsel opted not to contest the remand, and both men are currently held in custody, with their next appearance scheduled for September 18.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The legal proceedings represent a rare success story in the prosecution of borderless cyber-crimes. By focusing on the physical location of the actors—despite their global digital reach—the AFP has provided a blueprint for how domestic law enforcement can tackle threats that were previously considered untouchable due to jurisdictional complexity.

The Lasting Legacy: A Hardened Software Ecosystem

While the arrest of Thomson and Gaebler effectively decapitates the TeamPCP leadership, the legacy of their activities will persist in the form of structural changes to software security. Their brazen attacks served as a catalyst for a global "security wakeup" within the open-source community.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The most notable outcome of the TeamPCP spree is the widespread adoption of "cooldown periods" for software updates. Platforms like GitHub have now implemented mechanisms that delay the automatic deployment of new versions of packages, providing a window for security researchers to identify potential compromises before they are pushed to thousands of production systems.

Furthermore, the industry is seeing a renewed focus on "software bills of materials" (SBOMs) and more rigorous verification of developer identities. As experts have noted, while TeamPCP was a highly destructive actor, their actions highlighted the catastrophic vulnerabilities inherent in a system built on blind trust.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security

The case of TeamPCP underscores a shifting paradigm in cybersecurity: the threat actor is no longer always a state-sponsored entity with unlimited resources, but potentially an individual or a small group of highly capable, ideologically or financially motivated individuals. As these actors increasingly leverage Artificial Intelligence to compress the time between research and exploitation, the focus of the cybersecurity industry must necessarily shift from reactive defense to proactive, structural integrity, ensuring that the software foundations upon which the modern global economy rests are no longer susceptible to the whims of individual bad actors.

By Asro

Leave a Reply

Your email address will not be published. Required fields are marked *