Australian Authorities Arrest Alleged TeamPCP Members Behind Widespread Supply Chain Attacks
Australian authorities have apprehended two individuals suspected of being key members of **TeamPCP**, a notorious cybercrime syndicate responsible for an unprecedented series of software supply chain attacks. The arrests follow a lengthy investigation into the group's activities, which involved embedding malicious code into open-source software and extorting thousands of global businesses.
Authorities in Australia have arrested two men believed to be members of **TeamPCP**, a prolific cybercrime and data extortion group blamed for perpetrating the longest-running spree of software supply chain attacks ever.
In a statement released today, the **Australian Federal Police** (AFP) announced the arrest of two men from Western Australia, aged 21 and 23. They were taken into custody in connection with a βsophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.β While the AFP did not name the suspects, investigations have linked one of the individuals to **TeamPCP**'s self-described spokesperson.
**TeamPCP** emerged on the cybercrime scene in late 2025, embedding malicious code into hundreds of open-source software tools and extorting victims for profit. The group gained notoriety by compromising corporate cloud environments using a self-propagating worm dubbed **Shai-Hulud**. This worm injected malicious code into open-source programs maintained by developers whose credentials at public code repositories like **GitHub** or **NPM** were phished or stolen.
Journalist **Andy Greenberg**, writing for *Wired*, described **TeamPCP**βs core tactic as a cyclical exploitation of software developers.
βThe hackers gain access to a network where an open source tool commonly used by coders is being developed,β Greenberg wrote in May. βThe hackers plant malware in the tool that ends up on other software developersβ machines, including some who are writing other tools intended to be used by coders. The malware allows **TeamPCP**βs hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and **TeamPCP**βs collection of breached networks grows.β
**TeamPCP** also implemented a unique recruitment strategy. In May, the source code for the third iteration of **Shai-Hulud** was published online, followed by a contest offering $1,000 in virtual currency to participants who could conduct the largest supply chain operation using the worm's code. Participants were scored based on the number of weekly and monthly downloads of compromised packages, directly incentivizing them to target popular code libraries.

Security firm **Dataminr** noted, β**TeamPCP** has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participantsβ campaigns.β The $1,000 Monero (XMR) prize was described as a βparticipation trophy,β with the true incentive being talent identification and large-scale malicious access acquisition.
In March, **TeamPCP** executed a supply chain attack targeting AI infrastructure by compromising the code for **LiteLLM**, an open-source AI gateway. A recent analysis by security firm **CloudSEK** revealed that **TeamPCP**'s attack on **LiteLLM** harvested cloud service keys and other secrets from over 2,500 organizations, including many leading technology companies.
In May, **TeamPCP** claimed responsibility for compromising at least 3,800 code repositories at the **Microsoft**-owned **GitHub**, after a GitHub developer installed a code extension compromised by **TeamPCP**βs malware.
## Meet the Cybercats
Security experts characterize **TeamPCP** less as a singular hacker group and more as an amalgamation of threat actors from various cybercriminal gangs collaborating towards common goals.
**Austin Larsen**, a principal threat analyst with the **Google Threat Intelligence Group**, stated, βIt is not a structured criminal crew with a single operator. It is a peer community of individually-skilled actors, with one clear center of gravity.β
That center of gravity is **George Prepakis**, an accomplished security researcher and exploit developer who operates the Twitter/X profile @kernelstub. Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created, dubbed βCybercats.β **TeamPCP** and several other cybercrime entities have used this server for daily communication for months.

@kernelstub, like other administrators in the Cybercats chat, used his Twitter/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and ongoing conversations. In numerous instances, the corresponding X accounts for Cybercats members publicly taunted cybercrime victims before incidents were reported in the news media.
The Cybercats administrator β**Boxturtle**β is a close associate of **TeamPCP** and has been tweeting about the groupβs conquests under the name @xpl0itrs. This handle corresponds to a data breach broker active on **Breachforums** and **Darkforums**, who has been selling data stolen in recent breaches at automobile manufacturers, including **BMW Group**, **Audi**, **Honda**, **Mercedes-Benz**, **Volvo**, and **Toyota**, as well as data allegedly taken from **Snapchat** and **SportRadar**.

The Cybercats administrator β**SeesawSec**β is the alias behind the cybercrime group known as **Fulcrumsec**, which recently claimed credit for data extortion attacks against pharmaceutical giant **Novo Nordisk**, data broker **LexisNexis**, and **Avnet**, a Fortune 500 distributor of electronic components.

The Cybercats administrator β**@pcpcasper**β has also used a similar name on X to discuss **TeamPCP**βs attacks and victims. This individual has an extensive message history on Telegram, where shared videos and messages indicate **@pcpcasper** is an active member of the National Socialist Network, a neo-Nazi political organization based in Australia. Videos and images shared by **@pcpcasper** suggested their location in Western Australia. A source close to the investigation indicated that **@pcpcasper** was one of the two individuals arrested, a claim supported by messages posted online by @kernelstub.
The Cybercats member roster also features an administrator with the username β**T**,β which is short for the now-banned Twitter/X profile **@pcpcats**, the account operated by the self-described **TeamPCP** spokesperson.