VYPR
breachPublished Aug 27, 2026· 5 sources

Two Alleged 'TeamPCP' Hackers Arrested in Australia Amid Supply Chain Attack Spree

Australian authorities have arrested two individuals suspected of being part of the notorious TeamPCP cybercrime group, known for its extensive software supply chain attacks.

Australian Federal Police (AFP) have apprehended two men in Western Australia, aged 21 and 23, who are believed to be members of the cybercrime syndicate known as TeamPCP. This group has been linked to a prolonged and sophisticated campaign of software supply chain attacks, embedding malicious code into open-source software and targeting thousands of global businesses. The AFP stated the arrests are connected to a syndicate that allegedly created malicious open-source software to defraud businesses worldwide.

TeamPCP gained notoriety in late 2025 for its widespread compromise of open-source tools. Their primary tactic involved injecting malicious code into popular software libraries, often by exploiting compromised credentials of developers on platforms like GitHub and NPM. This allowed them to propagate malware, steal sensitive information, and gain further access to development environments. The group's methods created a cyclical exploitation loop, where compromised tools were used to develop and distribute further malicious software, expanding their reach.

A particularly notable aspect of TeamPCP's operations was their use of a self-propagating worm dubbed 'Shai-Hulud.' This worm was instrumental in compromising corporate cloud environments by adding malicious code to open-source programs. The group actively encouraged further exploitation by releasing the source code for Shai-Hulud and hosting a contest offering cryptocurrency rewards for participants who could conduct the most successful supply chain operations using the worm's code. This contest served as a recruitment and talent-identification mechanism, with TeamPCP promising substantial payments for valuable access harvested.

In March 2026, TeamPCP targeted the artificial intelligence sector by compromising LiteLLM, an open-source gateway used to connect with numerous large language models. Security firm CloudSEK reported that this attack alone harvested cloud service keys and other secrets from over 2,500 organizations, including major technology companies. The group also claimed responsibility for compromising at least 3,800 code repositories on GitHub after a developer installed a compromised code extension.

Security experts describe TeamPCP not as a traditional, rigidly structured group, but rather as a collaborative community of skilled threat actors from various cybercriminal gangs. Austin Larsen, a principal threat analyst at Google Threat Intelligence, noted that the group has a clear 'center of gravity' around George Prepakis, also known online as @kernelstub. Prepakis reportedly created a Matrix chat server named 'Cybercats,' which has served as a communication hub for TeamPCP and other associated cybercrime entities.

Within the 'Cybercats' community, members have used handles linked to distinct cybercrime groups, indicating a high degree of collaboration. One prominent associate, known as 'Boxturtle' (@xpl0itrsturtle), is reportedly a data breach broker active on forums like Breachforums and Darkforums, selling data stolen from various high-profile breaches, including those affecting major automobile manufacturers and companies like Snapchat and SportRadar.

The arrests in Australia mark a significant law enforcement action against a group that has demonstrated remarkable persistence and innovation in the realm of software supply chain attacks. The ongoing investigations into TeamPCP's activities are expected to shed further light on the complex networks of threat actors involved and their methods for infiltrating global software development pipelines.

The group's reliance on open-source software, a cornerstone of modern development, highlights a critical vulnerability in the digital ecosystem. Their sophisticated tactics, including the use of worms and incentivized hacking contests, underscore the evolving nature of cybercrime and the challenges faced by security professionals in defending against such pervasive threats.

Australian police have charged two individuals, Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, in connection with the TeamPCP cybercrime group. The charges, totaling 14 offences, stem from alleged involvement in the March 2026 supply chain attacks that compromised security scanners Trivy and Checkmarx KICS, as well as the AI gateway LiteLLM. The arrests follow the execution of search warrants and seizure of electronic devices.

Australian authorities have revealed that the two men charged are alleged to be "principal participants" in the TeamPCP syndicate, which has been linked to compromising over 1,000 organizations globally. The investigation, a collaboration between Australian Federal Police and the FBI, estimates that TeamPCP's activities led to the exposure of over 500,000 credentials and the theft of at least 300 gigabytes of data, with global remediation costs reaching hundreds of millions of dollars.

The arrests of Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, in Perth, Australia, are part of a broader international effort against the TeamPCP group. Australian Federal Police seized devices and are continuing their investigation, indicating that further arrests and charges are not ruled out. The group is accused of compromising supply chains and developer tools, leading to the exfiltration of over 300 GB of data from more than 1,000 organizations worldwide.

The arrests of the two alleged TeamPCP members in Western Australia follow a joint investigation by the Australian Federal Police, FBI, and Western Australia Police Force. The 21-year-old and 23-year-old men are accused of compromising open-source software to conduct global supply chain attacks, with the younger suspect facing eight charges including possession of illegal items.

Synthesized by Vypr AI