Australian authorities have arrested two men in Perth, identified as Ruben Thomson and Michael Gaebler, for their roles in the prolific TeamPCP cybercrime syndicate’s global software supply chain attacks.
Key Points
- The Australian Federal Police arrested the two suspects, aged 21 and 23, for allegedly creating malicious open-source software to target thousands of businesses.
- TeamPCP utilized a self-propagating worm called Shai-Hulud to compromise corporate cloud environments and steal credentials from public repositories like GitHub and NPM.
- The group’s activities included a March 2026 attack on the AI gateway LiteLLM, which exposed cloud service keys for over 2,500 organizations.
- Investigations linked the group to a "Cybercats" chat server, where members coordinated attacks and taunted victims, often leaving significant digital footprints.
- The arrests follow a series of high-profile breaches affecting major companies, including Honda, Toyota, and Novo Nordisk.