Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2815+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Two Alleged TeamPCP Supply-Chain Hackers Arrested in Australia
Two Alleged TeamPCP Supply-Chain Hackers Arrested in Australia
NEWS

Two Alleged TeamPCP Supply-Chain Hackers Arrested in Australia

AFP charges two Western Australia men with 14 cybercrime offenses tied to TeamPCP's Shai-Hulud worm and LiteLLM, GitHub supply-chain attacks.

Dylan H.

News Desk

September 13, 2026
3 min read

AFP Charges Two Over "Longest Running" Supply-Chain Spree

The Australian Federal Police (AFP) arrested two Western Australia men believed to be members of TeamPCP, a cybercrime and data-extortion group the AFP describes as responsible for "the longest running spree of software supply chain attacks ever." Ruben Ian Thomson, 21, of Cottesloe, Perth, and Michael Gaebler, 23, were taken into custody in the week of August 26-27, 2026. Thomson was denied bail and remains in custody. Both defendants are due in Perth Magistrates Court on September 18, 2026.

Combined, the pair face 14 cybercrime offenses. The AFP described TeamPCP as "a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses."


What TeamPCP Is Accused Of

TeamPCP emerged in late 2025 and built its reputation embedding malicious code across hundreds of open-source repositories, propagated via the self-spreading worm Shai-Hulud, which harvests developer credentials from GitHub and npm accounts. Named incidents tied to the group include:

IncidentScale
LiteLLM compromise (March 2026)2,500+ organizations, 434,000+ CI/CD pipelines affected
GitHub compromise (May 2026)3,800+ repositories claimed compromised
Automaker data theftBMW, Audi, Honda, Mercedes-Benz, Volvo, Toyota named as affected
Other named victimsSnapchat, LexisNexis, Novo Nordisk, SportRadar

Labs has separately covered several of these campaigns, including the LiteLLM supply-chain fallout and the broader Shai-Hulud npm worm activity, as the group's footprint expanded across the software supply chain over the past several months.


A Wider Cast of Characters

KrebsOnSecurity also connects the arrests to George Prepakis, who allegedly operates under the alias "@kernelstub" and runs Cybercats, a Matrix chat server reportedly used by TeamPCP and affiliated cybercrime groups to coordinate. Prepakis's role and legal status weren't detailed as part of this arrest action.


Why It Matters

TeamPCP's activity has been one of the more disruptive forces in software supply-chain security through 2026, chaining credential-harvesting worms to reach downstream victims that never directly interacted with the group. Arrests don't necessarily end an operation of this scale — Shai-Hulud-style worms and the credentials they've already harvested can keep circulating independently of the individuals now facing charges — but a court date and formal charges give defenders their first concrete look at who investigators believe was behind the campaign, and may surface further detail on the group's infrastructure and remaining members as the case proceeds.

#TeamPCP#Supply Chain#Shai-Hulud#Arrest#Australia#AFP

Related Articles

Australian Police Charge Two Men Over TeamPCP Supply Chain Attacks

AFP charges two Western Australian men over TeamPCP's March 2026 compromise of Trivy, Checkmarx KICS, and LiteLLM in a global supply chain campaign.

2 min read

TeamPCP Ups the Game, Releases Shai-Hulud Worm's Source Code

The hacking group TeamPCP has publicly released the source code for its Shai-Hulud supply chain worm, actively encouraging other threat actors to...

5 min read

GitHub Confirms Being Hacked by TeamPCP, Says Customer Data

GitHub has officially confirmed it was breached by the TeamPCP threat actor after the group advertised stolen internal source code on a cybercrime forum....

5 min read
Back to all News