Back to Feed
Supply ChainAug 27, 2026

Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos

Two alleged TeamPCP members arrested in Australia for software supply-chain attacks.

Summary

Two men from Western Australia have been arrested and charged for their alleged involvement in the cybercrime group TeamPCP, which compromised over 1,000 organizations by injecting malicious code into open-source software. The arrests follow months of disruption, including attacks on Trivy and malware targeting libraries like TanStack and UiPath, potentially exposing hundreds of thousands of credentials and costing millions in cleanup. Researchers traced one suspect through leaked passwords and online profiles, linking him to the group's infrastructure.

Full text

Two men from Western Australia were arrested and charged Wednesday for their alleged roles in TeamPCP, a notorious cybercrime group responsible for inserting malicious code into widely used open-source software in a campaign that compromised more than 1,000 organizations worldwide. Australian authorities did not formally name the men, but Australian media identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Police arrested both after searching properties, seizing electronic devices for forensic testing in the process. Thomson faces eight charges, including four counts of unauthorized data modification, dealing in criminal proceeds worth $100,000 or more, and refusal to comply with an order to hand over device passwords. Gaebler faces six related counts. The Australian Federal Police, which worked with the Western Australia Police Force (WAPF) and the Federal Bureau of Investigation, allege both men were part of a syndicate engaged in “data intrusion, identity crime and cryptocurrency-based money laundering.” Investigators said further arrests have not been ruled out. “These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide,” said Brett Leatherman, assistant director of the FBI’s Cyber Division. “We are proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks.” Months of havoc TeamPCP has been one of the most active cybercriminal groups in 2026. In late February, TeamPCP exploited a misconfigured workflow in Trivy, Aqua Security’s widely used vulnerability scanner, and stole a service-account token. Aqua replaced its credentials but missed some. On March 19, the group pushed a malicious Trivy release through every distribution channel at once, placing malware inside thousands of automated build pipelines. Downstream victims included the European Commission and GitHub. Investigators estimate the campaign exposed more than 500,000 credentials, removed at least 300 gigabytes of data and produced global cleanup costs in the hundreds of millions of dollars.In May, a piece of self-replicating malware known as “mini Shai-Hulud” targeted prominent software libraries, including TanStack, UiPath, and MistralAI, embedding credential-stealing code into development tools downloaded millions of times a week. Earlier this month, Oligo Security shared exclusive research with CyberScoop that dated the group’s attacks as far back as 2020. Cat photos and GitHub accounts Alongside the arrests, researchers at the Canadian threat intelligence firm Flare published research that traced Ruben Thomson’s online presence. Working from a GitHub alias, DeadCatx3, the researchers found a bug-bounty account under the name Ruben Thomson and a profile listing masscan[.]cloud, a domain that served as command server for mini Shai-Hulud. From there, a password tied to a school email address led researchers to databases of stolen credentials and a trove of accounts: a personal Google account, a TikTok profile under Thomson’s name, and a Steam gaming page showing a cat seated before several monitors. The cat image appeared on a TeamPCP Telegram identity. Flare assessed with high confidence that Thomson ran the group and said it confirmed the findings with law enforcement. Charlie Eriksen, lead malware researcher at Aikido Security, called the arrests a “relief,” but warned that the actions won’t mean the threat toward open-source software suddenly vanishes. “The conditions that produced them haven’t gone away, so there will be another TeamPCP,” he told CyberScoop in an email. “We just don’t know their name yet.”The two men will appear in Australian court Thursday. Share Facebook LinkedIn Twitter Copy Link

Indicators of Compromise

  • domain — masscan[.]cloud
  • malware — mini Shai-Hulud

Entities

TeamPCP (threat_actor)Trivy (product)Aqua Security (vendor)TanStack (product)UiPath (product)MistralAI (product)