Skip to main content
Emerging ThreatsMalware & Ransomware

Australian Police Disrupt TeamPCP Cybercrime Syndicate

Two young men in casual clothes sit in a formal setting with a blurred AFP emblem behind them, one looking down and the…

"Blackhatting is fun," said the person identified in this reporting as Ellis, a self-described TeamPCP spokesperson — a blunt line that helps explain why, authorities say, two young men in Western Australia were arrested this week in a probe into one of the most disruptive software supply-chain campaigns in recent memory.

AFP arrests two men from Western Australia

The Australian Federal Police (AFP) announced arrests of two men, aged 21 and 23, in connection with what it described as a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." The AFP did not name the defendants in its statement; KrebsOnSecurity reports the 21-year-old suspect had been identified earlier. The AFP said the men face a combined 14 cybercrime offenses and were scheduled to appear in Perth Magistrates Court the day of the announcement.

An update to the record cited ABC News in Australia, which confirmed one arrested man as Ruben Ian Thomson of Cottesloe and identified the 23-year-old suspect thought to be @pcpcasper as Michael Gaebler, who was also arrested in Perth. ABC reported Thomson was denied bail; Mr. Gaebler's attorney reportedly did not request bail. Both men will be held in custody until a court appearance on September 18.

Shai-Hulud and the poisoned open-source pipeline

Security researchers credit TeamPCP with a campaign that began in late 2025 and involved embedding malicious code into hundreds of open-source packages. The group used a self-propagating worm dubbed Shai-Hulud to expand reach: the worm added malicious code to tools maintained by developers whose credentials were phished or stolen, then those poisoned tools propagated further compromises.

CloudSEK’s analysis of one major incident found TeamPCP’s attack on LiteLLM — an open-source AI gateway connecting to over 100 large language models — harvested cloud service keys and other secrets from more than 2,500 organizations. TeamPCP claimed to have compromised at least 3,800 GitHub repositories after a compromised code extension was installed by a GitHub developer, according to reporting cited in this account.

Recruitment by contest and commercial incentives

TeamPCP did not limit itself to direct exploitation. The group published source code for Shai-Hulud’s third iteration and ran a contest offering 1,000 XMR (Monero) to whoever could conduct the largest supply-chain operation using the worm’s code. Dataminr warned the contest functioned as talent identification: the $1,000 prize was a floor, and organizers said they would pay more for "meaningful access" harvested by participants.

Cybercats, @kernelstub, and a distributed center of gravity

Researchers describe TeamPCP less as a tightly hierarchical gang than as an amalgam of actors collaborating in a peer community. Austin Larsen of the Google Threat Intelligence Group told reporters that the group is "a peer community of individually-skilled actors, with one clear center of gravity." That center is reported to be George Prepakis, who operates the Twitter/X profile @kernelstub and created a public Matrix server called "Cybercats" where TeamPCP and allied criminal actors communicated daily.

The Cybercats server included administrators and handles tied to multiple other cybercrime personas and groups — including "Boxturtle" (linked to a data-broker handle @xpl0itrsturtle) and "SeesawSec" (linked to the group Fulcrumsec). Several members used their Twitter/X names in Matrix discussions and in some cases publicly taunted victims before incidents were reported in the press.

The digital breadcrumb trail: aliases, servers, and registrations

Investigative reporting traced an overlapping web of aliases, emails, IP addresses and domain registrations back to a person publicly known in the chats as Ellis (also using forum handles including BulkDMT, Express, Persy_PCP and Deadcatx3). Intelligence firms cited in this reporting found forum registrations tied to the email shitstickpp@gmail.com and linked that address and other aliases to activity from IP addresses in South Africa and Perth, Australia.

Passive DNS records showed a Perth IP (211.27.196.111) hosting private family file servers. Open records and breach-tracking services connected Thomson-family domains and email addresses to social profiles and business registrations in Cottesloe, Western Australia. A HackerOne registration made in June 2025 under the name Ruben Thomson used the nickname Deadcatx3 — an alias security firms have associated with TeamPCP.

What this means for open-source maintainers, law enforcement, and technologists

  • Open-source maintainers: The incidents underscore the risk of stolen maintainer credentials and automated dependency updates. GitHub and other platforms have implemented "cooldown" mechanisms to slow automatic updates while maintainers and security tools inspect new releases.
  • Law enforcement and prosecutors: The AFP arrests show investigators using a combination of open-source intelligence, passive DNS, forum tie-ins and platform records to move from online handles to real-world arrests; the case will proceed through the Perth Magistrates Court system.
  • Enterprise security teams and cloud operators: Analyses such as CloudSEK’s on LiteLLM demonstrate how supply-chain compromises can yield cloud keys and secrets at scale — a risk that will keep defenders focused on secrets management and runtime detection.

Charlie Eriksen of Aikido Security described TeamPCP’s mix of motivations as money, disruption, attention and ideology, and suggested the group's operational sloppiness paradoxically made it both noisier and in some ways more dangerous. Ellis — interviewed by KrebsOnSecurity before the arrests — said he would accept the consequences if arrested and expressed ambivalence about leaving cybercrime, echoing other reporting that traces the group’s rise from forum posts and public chat logs to the arrests this week.

Source: KrebsOnSecurity — "Two Alleged ‘TeamPCP’ Hackers Arrested in Australia"