VYPR
breachPublished Aug 27, 2026· Updated Aug 28, 2026· 9 sources

Two Alleged 'TeamPCP' Hackers Arrested in Australia Amid Supply Chain Attack Spree

Australian authorities have arrested two individuals suspected of being part of the notorious TeamPCP cybercrime group, known for its extensive software supply chain attacks.

Australian Federal Police (AFP) have apprehended two men in Western Australia, aged 21 and 23, who are believed to be members of the cybercrime syndicate known as TeamPCP. This group has been linked to a prolonged and sophisticated campaign of software supply chain attacks, embedding malicious code into open-source software and targeting thousands of global businesses. The AFP stated the arrests are connected to a syndicate that allegedly created malicious open-source software to defraud businesses worldwide.

TeamPCP gained notoriety in late 2025 for its widespread compromise of open-source tools. Their primary tactic involved injecting malicious code into popular software libraries, often by exploiting compromised credentials of developers on platforms like GitHub and NPM. This allowed them to propagate malware, steal sensitive information, and gain further access to development environments. The group's methods created a cyclical exploitation loop, where compromised tools were used to develop and distribute further malicious software, expanding their reach.

A particularly notable aspect of TeamPCP's operations was their use of a self-propagating worm dubbed 'Shai-Hulud.' This worm was instrumental in compromising corporate cloud environments by adding malicious code to open-source programs. The group actively encouraged further exploitation by releasing the source code for Shai-Hulud and hosting a contest offering cryptocurrency rewards for participants who could conduct the most successful supply chain operations using the worm's code. This contest served as a recruitment and talent-identification mechanism, with TeamPCP promising substantial payments for valuable access harvested.

In March 2026, TeamPCP targeted the artificial intelligence sector by compromising LiteLLM, an open-source gateway used to connect with numerous large language models. Security firm CloudSEK reported that this attack alone harvested cloud service keys and other secrets from over 2,500 organizations, including major technology companies. The group also claimed responsibility for compromising at least 3,800 code repositories on GitHub after a developer installed a compromised code extension.

Security experts describe TeamPCP not as a traditional, rigidly structured group, but rather as a collaborative community of skilled threat actors from various cybercriminal gangs. Austin Larsen, a principal threat analyst at Google Threat Intelligence, noted that the group has a clear 'center of gravity' around George Prepakis, also known online as @kernelstub. Prepakis reportedly created a Matrix chat server named 'Cybercats,' which has served as a communication hub for TeamPCP and other associated cybercrime entities.

Within the 'Cybercats' community, members have used handles linked to distinct cybercrime groups, indicating a high degree of collaboration. One prominent associate, known as 'Boxturtle' (@xpl0itrsturtle), is reportedly a data breach broker active on forums like Breachforums and Darkforums, selling data stolen from various high-profile breaches, including those affecting major automobile manufacturers and companies like Snapchat and SportRadar.

The arrests in Australia mark a significant law enforcement action against a group that has demonstrated remarkable persistence and innovation in the realm of software supply chain attacks. The ongoing investigations into TeamPCP's activities are expected to shed further light on the complex networks of threat actors involved and their methods for infiltrating global software development pipelines.

The group's reliance on open-source software, a cornerstone of modern development, highlights a critical vulnerability in the digital ecosystem. Their sophisticated tactics, including the use of worms and incentivized hacking contests, underscore the evolving nature of cybercrime and the challenges faced by security professionals in defending against such pervasive threats.

Australian police have charged two individuals, Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, in connection with the TeamPCP cybercrime group. The charges, totaling 14 offences, stem from alleged involvement in the March 2026 supply chain attacks that compromised security scanners Trivy and Checkmarx KICS, as well as the AI gateway LiteLLM. The arrests follow the execution of search warrants and seizure of electronic devices.

Australian authorities have revealed that the two men charged are alleged to be "principal participants" in the TeamPCP syndicate, which has been linked to compromising over 1,000 organizations globally. The investigation, a collaboration between Australian Federal Police and the FBI, estimates that TeamPCP's activities led to the exposure of over 500,000 credentials and the theft of at least 300 gigabytes of data, with global remediation costs reaching hundreds of millions of dollars.

The arrests of Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, in Perth, Australia, are part of a broader international effort against the TeamPCP group. Australian Federal Police seized devices and are continuing their investigation, indicating that further arrests and charges are not ruled out. The group is accused of compromising supply chains and developer tools, leading to the exfiltration of over 300 GB of data from more than 1,000 organizations worldwide.

The arrests of the two alleged TeamPCP members in Western Australia follow a joint investigation by the Australian Federal Police, FBI, and Western Australia Police Force. The 21-year-old and 23-year-old men are accused of compromising open-source software to conduct global supply chain attacks, with the younger suspect facing eight charges including possession of illegal items.

The arrests of Ruben Ian Thomson and Louis Michael Gaebler in Australia mark a significant development in the ongoing investigation into the TeamPCP cybercrime group. Beyond the arrests, new research from Flare has traced Thomson's online presence, linking him to the "DeadCatx3" GitHub alias and a command server domain used in the "mini Shai-Hulud" campaign. This detailed attribution provides further evidence of Thomson's alleged leadership role within the group.

The investigation into the TeamPCP syndicate has led to the arrest of two Western Australian men, who face a combined 14 charges including unauthorized modification of data and dealing with proceeds of crime. These arrests follow parallel investigations by the Australian Federal Police (AFP) and the FBI, which began in April 2026 after multiple cyber threat intelligence firms flagged the campaign. Authorities estimate the malicious code potentially compromised over 1,000 organizations globally, leading to the theft of more than 500,000 credentials and 300GB of data, with remediation costs potentially reaching hundreds of millions of dollars.

The new reporting provides further detail on the alleged methods used by the TeamPCP group, including the exploitation of a misconfigured GitHub Actions workflow in Aqua Security's Trivy scanner and the subsequent pushing of a malicious Trivy release. It also details how the group leveraged access gained through Trivy to steal a publishing token for LiteLLM and release backdoored versions of that library, linking them to the Mini Shai-Hulud worm that targeted npm and PyPI repositories.

The Australian Federal Police (AFP) have arrested two men, aged 21 and 23, in Perth, who are alleged to be masterminds behind the TeamPCP cybercrime group. The FBI provided assistance in the operation, which followed an investigation initiated in April 2026 after information was received about the syndicate's activities. The arrested individuals are believed to have been principal participants who received cryptocurrency payments for their roles in inserting malicious code into open-source repositories and developing the Shai-Hulud worm.

Synthesized by Vypr AI