Australian authorities dismantle TeamPCP cybercrime syndicate behind historic software supply chain attack spree

The Australian Federal Police (AFP) have successfully concluded a high-stakes investigation into TeamPCP, a sophisticated and prolific cybercrime syndicate responsible for what is now considered the longest-running and most damaging software supply chain attack campaign in history. Two men from Western Australia, aged 21 and 23, were taken into custody following a coordinated operation involving the AFP, the Federal Bureau of Investigation (FBI), and Western Australia Police. The suspects, identified as Ruben Ian Thomson and Michael Gaebler, are alleged to have orchestrated a series of global breaches that compromised thousands of businesses by poisoning open-source software repositories.

The arrests mark a significant turning point in the fight against supply chain exploitation. The group’s activities, which gained momentum in late 2025, represented a paradigm shift in how threat actors target corporate infrastructure. By embedding malicious code directly into the foundational tools used by software developers, TeamPCP bypassed traditional perimeter defenses, effectively turning the trusted update mechanisms of major development platforms into delivery vectors for their malicious payloads.
The Rise and Tactics of the Shai-Hulud Worm
At the heart of TeamPCP’s operation was a self-propagating worm dubbed Shai-Hulud. Unlike conventional malware that relies on static distribution, Shai-Hulud functioned as a cyclical exploit engine. The group’s modus operandi involved gaining initial access to a developer’s network—often via phished or stolen credentials from platforms like GitHub or NPM—and subsequently injecting malicious code into widely used open-source libraries.

The brilliance and danger of the tactic lay in its recursive nature. Once the malicious code was integrated into a tool, it was distributed to unsuspecting developers worldwide. When these developers utilized the infected tools to build their own software, they inadvertently distributed the malware further. This created a compounding effect where each breach served as a staging ground for the next, allowing TeamPCP to exponentially increase its footprint across the global software ecosystem.
Security researchers have noted that TeamPCP’s influence extended beyond mere technical exploitation; they also mastered the art of social engineering and recruitment. In May 2026, the group published the source code for the third iteration of Shai-Hulud online, accompanying it with a $1,000 bounty competition. By rewarding participants based on the number of downloads their compromised packages received, TeamPCP effectively incentivized independent hackers to target the most popular and vulnerable code libraries, essentially outsourcing their malicious operations to a wider community of threat actors.

A Timeline of Escalation and Impact
The timeline of TeamPCP’s operations reveals a rapid escalation in both scale and ambition. While early activities in 2025 focused on smaller repositories, the group soon moved toward high-value targets.
In March 2026, the syndicate executed a high-profile attack on LiteLLM, an open-source AI gateway. By compromising the core code of this infrastructure, the group gained access to cloud service keys and sensitive secrets belonging to more than 2,500 organizations, including some of the world’s most prominent technology firms. This breach underscored the vulnerability of AI-driven supply chains, where the interconnectedness of large language models provides a massive, unified attack surface.

Following this, in May 2026, TeamPCP claimed responsibility for breaching approximately 3,800 code repositories on GitHub. The compromise was triggered by a single developer installing a malicious browser extension, illustrating how easily a minor lapse in individual operational security can lead to systemic failure.
The Anatomy of the Cybercats Network
Intelligence gathered by firms such as Google Threat Intelligence and Intel 471 suggests that TeamPCP was not a traditional, rigid criminal hierarchy. Instead, it operated as a loose, fluid amalgamation of threat actors who occasionally pooled their resources. This collective, which communicated via a Matrix server dubbed "Cybercats," included individuals from disparate cybercrime gangs.

Among the key figures identified in the Cybercats network were administrators using handles such as "Boxturtle" and "SeesawSec." These individuals were linked to various data extortion campaigns targeting major corporations, including BMW, Audi, and pharmaceutical giant Novo Nordisk. The investigation into these figures—particularly the leader known as "Ellis"—revealed a trail of digital breadcrumbs that ultimately led to the doorstep of Ruben Thomson in Cottesloe, Western Australia.
Thomson’s downfall was largely attributed to a series of operational security (OPSEC) failures. Despite his technical proficiency in PHP development and server management, he frequently linked his criminal aliases—such as "Deadcatx3" and "BulkDMT"—to his real-world identity. His registration of legitimate business entities under names like "OPSEC Express" and his use of personal email addresses for forum registrations provided investigators with a clear roadmap to his location.

Official Responses and Legal Proceedings
The AFP’s statement confirmed that the two men arrested face a combined 14 cybercrime offenses. Following their appearance in the Perth Magistrates Court, Ruben Thomson was denied bail, while Michael Gaebler remained in custody. Both are scheduled for a subsequent court hearing on September 18. The severity of the charges reflects the Australian government’s increasing focus on protecting critical infrastructure and the digital economy from supply chain disruptions.
The arrests have been met with relief by the cybersecurity community, yet experts caution that the threat posed by similar groups remains high. Charlie Eriksen, a researcher at Aikido Security, highlighted the evolving nature of the threat landscape. "TeamPCP represented a new breed of threat actor—not quite state-sponsored, not purely ideological, but driven by a dangerous mix of technical capability, financial incentive, and a lack of moral restraint," Eriksen observed.

Broader Implications for Software Security
The legacy of TeamPCP will likely be defined by the industry’s response to their actions. Their success in exploiting the "trusted" nature of open-source publishing forced a long-overdue reckoning among major platform providers.
Most notably, the group’s campaign acted as a catalyst for Microsoft and GitHub to implement mandatory security safeguards, including the "three-day cooldown" mechanism for Dependabot. This feature, which delays the automatic application of dependency updates, is designed to provide security researchers and maintainers a window of opportunity to detect and mitigate malicious code before it reaches production environments.

Furthermore, the rise of artificial intelligence has significantly compressed the time required for threat actors to bridge the gap between theoretical research and operational deployment. As Eriksen noted, LLMs allow less-disciplined actors to operate at an unprecedented scale. This democratization of cyber-offensive capabilities means that future supply chain attacks may be faster, more frequent, and harder to detect than ever before.
The case of TeamPCP underscores the critical importance of a "zero-trust" approach to software development. The reliance on third-party libraries and open-source components has created a level of interdependence that, while efficient, introduces systemic risk. As the industry moves forward, the focus is shifting toward verifiable, signed software builds and more rigorous vetting processes for package maintainers.

While the primary operators of TeamPCP are currently facing the legal consequences of their actions, the digital infrastructure they exploited remains under constant scrutiny. The arrests in Western Australia serve as a stark reminder that in the interconnected world of modern software, security is not merely a technical challenge—it is a shared responsibility that requires constant vigilance, better tooling, and, as evidenced by this investigation, effective international collaboration between law enforcement and the security research community. The era of TeamPCP may have come to an end, but the vulnerabilities they exposed have fundamentally altered the landscape of software supply chain security for years to come.






