Australian Federal Police (AFP) have arrested two men in Western Australia, aged 21 and 23, who are believed to be key figures in the notorious cybercrime syndicate "TeamPCP." This group is infamous for orchestrating the longest-running spree of software supply chain attacks ever recorded, a sophisticated operation that allegedly targeted thousands of global businesses by embedding malicious code within open-source software. The arrests are the result of a collaborative effort involving the AFP, the FBI, and the Western Australia Police Force (WAPF), aimed at disrupting the syndicate’s operations.
While the AFP has not publicly named the defendants, KrebsOnSecurity has identified the 21-year-old suspect and has been in communication with him. This investigation delves into interviews with TeamPCP’s self-proclaimed spokesperson and analyzes the digital breadcrumbs left by the group’s leader, which may have contributed to their downfall.
TeamPCP emerged on the cybercrime landscape in late 2025, quickly establishing a reputation for injecting malicious code into numerous open-source software tools. Their modus operandi involved exploiting software supply chains to gain access to corporate cloud environments. A self-propagating worm, dubbed "Shai-Hulud," was central to their strategy, systematically adding malicious code to open-source programs. This was often achieved by compromising the credentials of developers at public code repositories like GitHub or NPM, through phishing or credential theft.

As journalist Andy Greenberg of Wired described, TeamPCP employed a cyclical exploitation strategy. Hackers would infiltrate networks where popular open-source tools were under development. There, they would plant malware that would then spread to other developers’ machines, including those working on other developer tools. This malware enabled TeamPCP to steal credentials, allowing them to publish malicious versions of these development tools, thus perpetuating a cycle of network breaches and expanding their compromised infrastructure.
Beyond direct exploitation, TeamPCP also engaged in a form of cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was released online, accompanied by a contest offering $1,000 in virtual currency (Monero) to participants who could execute the most significant supply chain operations using the worm’s code. The scoring criteria—based on weekly and monthly downloads of compromised packages—explicitly incentivized targeting popular code libraries. Security firm Dataminr reported that TeamPCP framed this competition as a recruitment opportunity, intending to purchase any valuable access harvested by participants. The prize money was dismissed as a mere "participation trophy," with the group emphasizing that significant finds would be compensated far more handsomely, confirming the contest’s dual purpose of talent identification and large-scale malicious access acquisition.
In March, TeamPCP executed a notable supply chain attack targeting AI infrastructure by compromising the code for LiteLLM, an open-source AI gateway connecting users to over 100 large language models. A subsequent analysis by CloudSEK revealed that this attack harvested cloud service keys and other sensitive information from more than 2,500 organizations, including many leading technology companies worldwide. Further escalating their reach, in May, TeamPCP claimed responsibility for compromising at least 3,800 code repositories on Microsoft-owned GitHub. This was facilitated by a GitHub developer who unknowingly installed a compromised code extension.

Security experts characterize TeamPCP not as a monolithic hacker group, but rather as an amalgamation of threat actors from various cybercriminal gangs who collaborate on shared objectives. Austin Larsen, a principal threat analyst at Google Threat Intelligence Group, stated, "It is not a structured criminal crew with a single operator. It is a peer community of individually-skilled actors, with one clear center of gravity."
This "center of gravity" is identified as George Prepakis, also known online as "@kernelstub," an accomplished security researcher and exploit developer. Prepakis created a Matrix chat server named "Cybercats," which has served as a daily communication hub for TeamPCP and other cybercrime entities for several months. Within these chats, members often used their real-world-associated online handles. @kernelstub frequently tweeted about conversations within the Cybercats chat, and members, using their online aliases, would often taunt potential victims publicly before incidents were reported.
One prominent Cybercats administrator, "Boxturtle" (@xpl0itrsturtle2), is a close associate of TeamPCP. Boxturtle operates as a data breach broker on platforms like Breachforums and Darkforums, selling data allegedly stolen from numerous automobile manufacturers, including BMW Group, Audi, Honda, Mercedes-Benz, Volvo, and Toyota, as well as data purportedly exfiltrated from Snapchat and SportRadar.

Another Cybercats administrator, "SeesawSec," is the alias for the operator of the cybercrime group Fulcrumsec. Fulcrumsec has recently claimed responsibility for data extortion attacks against pharmaceutical giant Novo Nordisk, data broker LexisNexis, and Avnet, a Fortune 500 electronic components distributor.
The Cybercats administrator "@pcpcasper" also uses a similar name on X to discuss TeamPCP’s attacks and victims. Extensive message history on Telegram reveals @pcpcasper to be an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia. Videos and images shared by this user, purportedly of their cat, have placed them in Western Australia, supporting the claim by an investigative source that @pcpcasper was one of the two individuals arrested.
The Cybercats roster also includes an administrator identified as "T," the former handle for the banned Twitter/X profile "@pcpcats," who is described as TeamPCP’s self-appointed spokesperson and was arrested today. @pcpcats also hails from Western Australia. Before @kernelstub invited him to the Cybercats server, @pcpcats posted infrequently, with other members often inquiring about his well-being. His absences were often attributed to his struggles with hallucinogens and other narcotics, which led to prolonged periods of wakefulness followed by extended periods of sleep.

The TeamPCP leader, @pcpcats, has utilized multiple aliases across cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These identities are linked by shared Tox ID and/or Session ID contact handles. BulkDMT was also known as "DMT Host," a virtual private server (VPS) hosting service advertised on Darkforums and Breachstars.
Cyber intelligence firm Intel 471 reports that "Express" registered on Breachforums using the email address [email protected]. During a two-month period in 2025, Express posted from four different Internet addresses located in South Africa. In July 2025, Express announced on Breachforums the sale of 14 gigabytes of data stolen from South Africa’s State Information Technology Agency.
Flashpoint, a threat intelligence platform, has recorded over a year’s worth of messages from the TeamPCP leader’s Telegram alter ego, "Persy_PCP." Persy_PCP claimed to split their time between two countries. In November 2025, when asked about a stolen data set, Persy_PCP explained, "I have these [files] as well, problem is these are in another country." Later that month, Persy_PCP complained, "My whole country is racist and they want people like me dead." Flashpoint records indicate that BulkDMT, in September 2025, expressed concerns about South Africa’s future, stating, "this country is going to fucking starve when they take the farmers land," likely referencing white landowners who claim to be targets of a genocide campaign. This aligns with public reporting; Cyberscoop reported in June that Google traced TeamPCP’s internet connections to South Africa, suggesting the primary operator was based there during at least some of their attacks.

BulkDMT also shared in a group chat on Breachforums about recovering from a methamphetamine addiction, stating, "My life is kinda fucked rn [right now], but that’s fine and there isn’t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don’t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that’s enough drive and meaning."
The identity threat protection company SpyCloud notes that [email protected] is linked to a "ChristmasSnow" account on Raidforums from 2022. Nearly all the IP addresses used to access this account originated from Internet Service Providers (ISPs) in Perth, Australia. KrebsOnSecurity’s investigation into passive DNS records maintained by DomainTools.com revealed that one of these Perth IP addresses, 211.27.196.111, was used for several years as a private file server by a Perth family with the surname Thomson. These records show at least three hosts—ithomson.direct.quickconnect.to, kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com—persisted at this address between 2022 and 2025.
A search for "joshuathomson39" on the breach tracking service Constella Intelligence uncovered an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open-source intelligence platform Epieos found that the phone number associated with this kwe.com account was used to register a Facebook profile for Josh Thomson, listing his family members as brother Ruben, father Ian, and mother Cindy. This Facebook profile also indicates that Josh and his family are originally from Pietermaritzburg, South Africa, but currently reside in Cottesloe, a suburb of Perth. A DomainTools search for Ian Thomson and Australia revealed five domains registered by the same registrant, including securecomputing.au, thomson.org.au, and thomsonfamily.net.au. Ian Thomson is a dentist in Cottesloe and graduated from The University of the Witwatersrand in Johannesburg, South Africa.

Constella finds that [email protected] registered several online accounts, but Josh himself appears to have minimal connection to dubious cybercrime forums. His brother, Ruben, however, has a significant presence in these communities, dating back to at least 2018. Constella reports that [email protected] frequently reused the password "joshuathomson1," which was also used by a handful of other accounts, including [email protected] and [email protected].
According to Intel 471, [email protected] was used to register the user "Yolosolo17" on the crime forum Altenen in 2018. This account was registered from the Perth address 110.141.230.15. On Altenen, Yolosolo17 advertised free web proxies and the domain rubenthomson.com, which at one point was used to sell steeply discounted iPhones. DomainTools confirms that rubenthomson.com was hosted at 110.141.230.15 and registered to [email protected].
SpyCloud reports that 10.141.230.15 was used by the email address [email protected] on Raidforums and [email protected] on Nulled. The same IP address was also used by [email protected], [email protected], and [email protected]. SpyCloud further indicates that the sheepstealing Gmail address is tied to the accounts Sheep420, YoloSolo117, and Yakuza.cc on Raidforums, and to the account "Sheep Stealing" on Hackforums. Intel 471 states that [email protected] was used to register the account DingoFlour on Breachforums in October 2023, as well as Sheepx on Altenen.

Epieos reports that [email protected] is linked to an Airbnb account for Ruben, who described himself as a web developer educated at the University of Western Australia and living abroad. "Hey, I’m Ruben, my friends call me Ellis. I’m a Perth creative who occasionally books rooms when visiting family and for photography." Epieos also found that [email protected] registered an upwork.com profile under the name Ruben, detailing his skills in setting up secure server hosting solutions and PHP full-stack web development. The profile reads, "I’m familiar with Linux, working with relational databases (SQL), I also script in Python mainly for writing social media bots."
Epieos further discovered that [email protected] is connected to a Microsoft account for Ruben Thomson and a now-defunct GitHub account called XmasSnow/XmasSnowisBack, which scammed users on forums in 2022 by claiming to sell exclusive exploits for newly released software patches. (Recall that [email protected] was used to register a forum account named ChristmasSnow). This same sheepstealing email address registered a Twitter/X account in 2026 called "Gone Fishing," listing its location as South Africa. This Gmail account has also left several reviews for businesses on Google Maps over the past seven years, all located on the west coast of Australia.
People search service Pipl finds a 21-year-old Ruben Thomson in Western Australia with a phone number ending in 979. A lookup of this number at Epieos reveals it is connected to a TikTok account under the name Ellis and a PayPal account in the name of Ruben Thomson. Finally, a search for Ruben Thomson from Cottesloe in Australia’s registered business records reveals he has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions, Tensor Industries, and OPSEC Express. The latter is particularly ironic, as "OPSEC" (operational security) refers to techniques for obscuring one’s identity online, and using a cybercrime handle in a company name is the antithesis of this practice.

Ruben Thomson also made a significant operational security (opsec) failure by registering on HackerOne, a bug bounty program, in June 2025. His chosen HackerOne username was "Deadcatx3," a nickname flagged by multiple security firms as an alias used by TeamPCP.
In early July 2026, KrebsOnSecurity interviewed the TeamPCP leader, referred to as Ellis, via Signal. Ellis claimed he ceased his involvement with TeamPCP in March 2026, prior to the LiteLLM attacks, and that another individual had since assumed leadership. He stated that a year earlier, he had completed a series of detox and sobriety programs and was two months sober when he reconnected with former associates from the malware development scene. "One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to," Ellis explained. "I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale." Ellis stated that prior to this, he was homeless and living in unstable conditions. He described blackhatting as "fun," offering "actual rewards and incentives to learn and you grow with your team." He added, "Without qualifications, no employer will even take the time to hear you out."
Ellis claimed to have earned approximately $20,000 for his activities with TeamPCP, asserting that it was never about money or fame. He doubted his experiences would prepare him for legitimate IT employment, stating, "I am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience. I no longer have to choose between rent and food for that I’m grateful and so are the team members." Ellis expressed no remorse for his cybercrime activities and seemed resigned to potential arrest, stating, "If I’ve already been found out then its out of my control, I’ll make peace with that. Honestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this."

Ellis’s messages on the group’s Matrix server indicate ongoing struggles with sobriety. On June 25, he informed @kernelstub of his intention to "trip" with his "homie," specifying "Ketty and some DMT," referring to ketamine and dimethyltryptamine (DMT), and the potential addition of "2cb." Approximately two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to surrender but needed to tie up loose ends. Less than 24 hours later, he posted an image on Telegram showing a yellowish powdered substance and vape cartridges, likely synthetic DMT.
The two defendants were arrested Wednesday morning. The AFP stated they face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today. Charlie Eriksen, a security researcher at Aikido Security who has closely monitored TeamPCP’s campaigns, described them as a new type of threat actor that defies easy categorization, blending motivations of money, disruption, attention, and ideology. Eriksen noted that large language models (LLMs) and artificial intelligence are increasingly bridging the knowledge gap for threat actors, enabling them to operate at scale without traditional operational discipline. This, he explained, can lead to more "noisy" actors who make mistakes and leave evidence, taking risks that professional groups would avoid, potentially making them more dangerous. Eriksen credited TeamPCP’s Shai-Hulud worm with improving supply chain security by forcing GitHub and other platforms to implement new safeguards, such as a three-day "cooldown" mechanism for Dependabot, designed to allow for the detection and removal of compromised package updates. Eriksen concluded that TeamPCP’s legacy is accelerating the adoption of crucial security measures that the community had struggled to implement for years.
Update, 10:08 a.m. ET: ABC News in Australia has confirmed that Ruben Ian Thomson of Cottesloe, age 23, is one of the two arrested individuals, believed to be @pcpcasper, Michael Gaebler. Thomson was denied bail, and Gaebler’s attorney reportedly did not request bail for his client. Both men will remain in custody until their next court appearance on September 18.

