AFP Charges Two Over "Longest Running" Supply-Chain Spree
The Australian Federal Police (AFP) arrested two Western Australia men believed to be members of TeamPCP, a cybercrime and data-extortion group the AFP describes as responsible for "the longest running spree of software supply chain attacks ever." Ruben Ian Thomson, 21, of Cottesloe, Perth, and Michael Gaebler, 23, were taken into custody in the week of August 26-27, 2026. Thomson was denied bail and remains in custody. Both defendants are due in Perth Magistrates Court on September 18, 2026.
Combined, the pair face 14 cybercrime offenses. The AFP described TeamPCP as "a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses."
What TeamPCP Is Accused Of
TeamPCP emerged in late 2025 and built its reputation embedding malicious code across hundreds of open-source repositories, propagated via the self-spreading worm Shai-Hulud, which harvests developer credentials from GitHub and npm accounts. Named incidents tied to the group include:
| Incident | Scale |
|---|---|
| LiteLLM compromise (March 2026) | 2,500+ organizations, 434,000+ CI/CD pipelines affected |
| GitHub compromise (May 2026) | 3,800+ repositories claimed compromised |
| Automaker data theft | BMW, Audi, Honda, Mercedes-Benz, Volvo, Toyota named as affected |
| Other named victims | Snapchat, LexisNexis, Novo Nordisk, SportRadar |
Labs has separately covered several of these campaigns, including the LiteLLM supply-chain fallout and the broader Shai-Hulud npm worm activity, as the group's footprint expanded across the software supply chain over the past several months.
A Wider Cast of Characters
KrebsOnSecurity also connects the arrests to George Prepakis, who allegedly operates under the alias "@kernelstub" and runs Cybercats, a Matrix chat server reportedly used by TeamPCP and affiliated cybercrime groups to coordinate. Prepakis's role and legal status weren't detailed as part of this arrest action.
Why It Matters
TeamPCP's activity has been one of the more disruptive forces in software supply-chain security through 2026, chaining credential-harvesting worms to reach downstream victims that never directly interacted with the group. Arrests don't necessarily end an operation of this scale — Shai-Hulud-style worms and the credentials they've already harvested can keep circulating independently of the individuals now facing charges — but a court date and formal charges give defenders their first concrete look at who investigators believe was behind the campaign, and may surface further detail on the group's infrastructure and remaining members as the case proceeds.