The Downfall of "TeamPCP": How a Chaotic Collective of "Cybercats" Redefined Supply Chain Warfare
In a sweeping operation that marks a turning point for global software supply chain security, the Australian Federal Police (AFP) have dismantled the core leadership of TeamPCP, a decentralized, prolific cybercrime collective responsible for arguably the longest-running and most destructive software supply chain attack spree in history.
Two men from Western Australia, aged 21 and 23, were taken into custody this week following a joint investigation involving the AFP, the FBI, and Western Australia Police. While authorities have maintained a policy of nondisclosure regarding the identities of the accused, court proceedings and investigative reporting have confirmed that the primary target was 21-year-old Ruben Ian Thomson, a resident of the affluent Perth suburb of Cottesloe. His associate, 23-year-old Michael Gaebler, was arrested alongside him.

The arrests signal the end of a chaotic, nine-month reign of terror that saw TeamPCP compromise thousands of global businesses, infiltrate major AI infrastructure, and turn the developer ecosystem against itself.
The Rise and Methodologies of TeamPCP
TeamPCP emerged in late 2025 as a disruptive force, operating not as a traditional, hierarchical criminal organization, but as a fluid "peer community" of threat actors. Security researchers at Google’s Threat Intelligence Group have described the group as an amalgamation of diverse hackers who shared infrastructure, tactics, and targets.

Their primary weapon was the Shai-Hulud worm, a self-propagating piece of malware designed to target the "human layer" of software development. By phishing or stealing credentials from developers on platforms like GitHub and NPM, the group injected malicious code into open-source software tools.
As journalist Andy Greenberg detailed, the attack vector was cyclical:

- Initial Compromise: Hackers gain access to a network where a popular open-source tool is maintained.
- Infection: Malicious code is embedded in the tool, which is then downloaded by other unsuspecting developers.
- Escalation: The malware steals credentials from those developers, allowing TeamPCP to publish malicious versions of their tools.
- Expansion: The cycle repeats, exponentially growing the group’s reach.
This strategy culminated in the March 2026 breach of LiteLLM, an open-source AI gateway. Security firm CloudSEK found that this single operation harvested cloud service keys and secrets from over 2,500 organizations, including some of the world’s most prominent technology firms.
Chronology of the "Cybercats" Era
The group’s operational hub was a Matrix chat server dubbed "Cybercats." Members of this group utilized the chat to coordinate daily, share stolen access, and taunt victims before their breaches were even publicly disclosed.

- 2025: TeamPCP begins its campaign. Ruben Thomson (using aliases like "Ellis," "BulkDMT," and "Deadcatx3") starts posting on cybercrime forums like Breachforums and Darkforums.
- Late 2025: The "Shai-Hulud" worm is deployed, marking a shift toward automated, large-scale supply chain exploitation.
- Early 2026: TeamPCP launches a recruitment contest, offering $1,000 in Monero to hackers who could successfully use their worm to compromise the most popular code libraries. This move was described by intelligence firm Dataminr as a "talent identification" exercise.
- March 2026: The LiteLLM breach occurs, exposing thousands of corporate environments.
- July 2026: Investigative journalists identify the physical location and identity of the group’s leadership via lax operational security (OPSEC).
- August 2026: The AFP conducts simultaneous raids in Western Australia, arresting Thomson and Gaebler.
The Anatomy of an OPSEC Failure
The downfall of TeamPCP is a masterclass in how even highly skilled technical actors can be undone by poor operational security. Despite their sophistication in exploiting complex software supply chains, the group’s leaders—particularly Thomson—left a digital trail that eventually linked their criminal personas to their real-world lives in Australia.
Investigators used passive DNS records, leaked database credentials, and even Google Maps reviews to triangulate the identities of the "Cybercats" admins. Thomson, who operated under the alias "Ellis," frequently conflated his professional developer identity with his criminal handles. For instance, he used the handle "Deadcatx3"—a known TeamPCP alias—to register an account on the bug-bounty platform HackerOne.

Furthermore, Thomson incorporated legitimate Australian companies with names like "OPSEC Express," a move that ironically highlighted the very lack of operational security that led to his identification. Investigators also found that he used the same email addresses and IP ranges for both his freelance Upwork development profile and his illicit forum activities.
In a candid interview with KrebsOnSecurity conducted via Signal shortly before his arrest, Thomson admitted to his struggles with substance abuse, including the use of ketamine and DMT. He expressed a resignation toward his inevitable capture, stating, "If I’ve already been found out then it’s out of my control, I’ll make peace with that."

Official Responses and Legal Consequences
The Australian Federal Police issued a stern warning following the arrests, emphasizing that global borders provide no protection for those engaged in international cybercrime.
"Two men from Western Australia have been charged in connection with a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses," the AFP statement read.

According to reports from the ABC News, Thomson was denied bail, while Gaebler’s counsel did not pursue a request for release. Both men face a combined 14 cybercrime offenses, with their next court appearance scheduled for September 18. The severity of the charges reflects the scale of the damage—not just in terms of financial theft, but in the erosion of trust within the global open-source ecosystem.
Implications for the Future of Software Security
Charlie Eriksen, a researcher at Aikido Security, argues that while TeamPCP was undeniably harmful, their actions served as a harsh, necessary wake-up call for the technology industry.

"They managed to wake up Microsoft to the fact that they had become negligent," Eriksen noted. By compromising the GitHub environment, TeamPCP forced the platform to implement critical safety features, such as the three-day "cooldown" mechanism for Dependabot updates. This feature, designed to prevent the automatic installation of malicious code, is now being adopted by other major coding ecosystems, including Python and JavaScript.
A New Breed of Threat Actor
TeamPCP represents a modern, hybrid threat. They do not fit the traditional mold of state-sponsored actors, nor are they purely ideologically driven. They are "noisy" and often reckless, utilizing Large Language Models (LLMs) to bridge the gap between theoretical research and operational exploitation.

This new class of criminal is increasingly dangerous because they operate at a speed that traditional defensive cycles cannot match. However, as the fall of TeamPCP proves, their lack of professional discipline—manifesting as public taunting, substance abuse-fueled erratic behavior, and poor digital hygiene—remains their greatest vulnerability.
The Road Ahead
The "Cybercats" era may be coming to a close, but the precedent they set—the commodification of supply chain attacks and the use of LLMs to scale malicious activity—will likely persist. The industry is now tasked with moving beyond reactive measures to proactive, platform-level security.

For the developers who were victims of these attacks, the lesson is clear: the era of blind trust in open-source dependencies is over. As Eriksen concluded, TeamPCP achieved in nine months what the security community had struggled to implement for years. Their legacy is a more resilient, albeit more cautious, digital infrastructure—a "participation trophy" that the tech world earned at a steep price.
