Arrestato in Australia il cuore di TeamPCP: migliaia di aziende colpite via open source
Malware

Illustrative image generated with AI

Heart of TeamPCP Arrested in Australia: Thousands of Companies Hit via Open Source

Australian police arrest cybercriminals behind open-source attacks affecting thousands of companies globally via malicious tools.

Text generated by artificial intelligence, published without human review. AI transparency

On 27 August 2026 the Australian Federal Police announced the arrest of two men, aged 21 and 23, in Western Australia. They are alleged members of a “sophisticated cybercriminal syndicate” that created malicious open source tools to rob thousands of companies globally. Their names have not been released, but sources close to the investigation indicate that one of the two is the user known as @pcpcasper, active in the Matrix chat “Cybercats” and associated with TeamPCP. The other is the group’s self-declared spokesperson, identified as T or @pcpcats.

TeamPCP emerged in late 2025 as an aggregation of actors from multiple criminal groups. It is not a hierarchical gang but a community of peers with a “clear center of gravity,” according to Austin Larsen, principal threat analyst at Google Threat Intelligence Group. The center of gravity is George Prepakis, a security researcher and exploit developer with the X profile @kernelstub. Prepakis created the Matrix server “Cybercats” and advertised it with a public invite link. For months TeamPCP and other criminal entities used it daily.

Shai-Hulud: The Worm That Spreads Among Developers

The group compromised corporate cloud environments with a self-propagating worm called Shai-Hulud. The malware added malicious code to open source programs maintained by developers whose credentials on public repositories like GitHub or NPM had been stolen or obtained through phishing. The cycle was simple: access a developer network, insert the malware into the open source tool, spread to other developers’ machines, steal new credentials to publish malicious versions of other packages. The pool of compromised networks grew with each iteration.

In May 2026, the source code of the third iteration of Shai-Hulud was published online. Shortly after, TeamPCP launched a contest with a prize of $1,000 in Monero for whoever conducted the most extensive supply chain operation using that code. Participants were evaluated based on the weekly and monthly download counts of the compromised packages. The stated goal: recruit talent and purchase significant access. The prize was described as a “recruitment floor” and “just a participation trophy.” The announcement was spread on Telegram.

LiteLLM and GitHub: The Two Most Serious Attacks

In March 2026 TeamPCP executed a supply chain attack against LiteLLM, an open source AI gateway that connects users to more than 100 large language models. According to CloudSEK, the attack collected cloud service keys and other secrets from more than 2,500 organizations, including many of the world’s leading tech companies.

In May 2026 the group claimed the compromise of at least 3,800 code repositories on GitHub, owned by Microsoft, after a platform developer installed a compromised code extension. Hundreds of open source tools were distributed in malicious versions. The AFP speaks of thousands of companies robbed globally.

In addition to supply chain attacks, group members sold stolen data. The administrator “Boxturtle,” active on X as @xpl0itrsturtle, is a breach broker on Breachforums and Darkforums and has sold data from BMW Group, Audi, Honda, Mercedes-Benz, Volvo, Toyota, Snapchat, and SportRadar. The alias “SeesawSec” is associated with the Fulcrumsec group, which has claimed data extortion attacks against Novo Nordisk, LexisNexis, and Avnet. The alias “Express” announced on Breachforums on 30 July 2025 the sale of access to 14 gigabytes of data from South Africa’s State Information Technology Agency.

Cybercats and the Community of Actors

Experts describe TeamPCP not as a structured gang, but as an aggregation of individually skilled actors who sometimes collaborate. The Matrix chat “Cybercats” was the operational hub. The main administrators were Boxturtle, SeesawSec, @pcpcasper, and T (@pcpcats).

@pcpcasper used the same name on X to comment on the group’s attacks and victims. His Telegram history shows a declared membership in the National Socialist Network, a neo‑Nazi political organization based in Australia. In chats he shared videos and images of his cat; several videos place him in Western Australia. A source close to the investigation told KrebsOnSecurity that @pcpcasper is one of the two arrested. This is supported by messages posted online by @kernelstub on the morning of 27 August 2026.

T, short for the X profile @pcpcats, was the self-declared spokesperson for TeamPCP and also comes from Western Australia. When @kernelstub tweeted the invite to the Matrix server, T posted only rarely. Other members attributed his prolonged absences to the use of hallucinogens and other substances.

The Mistakes That Led to Identification

The user @pcpcats used several nicknames on criminal forums: EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. The accounts are linked because they advertised the same Tox ID and/or Session ID. BulkDMT was also known as DMT Host, a virtual private server service sold on Darkforums and Breachstars. Express registered on Breachforums with the email [email protected] and posted for two months in 2025 using four IP addresses located in South Africa.

Flashpoint recorded over a year of Telegram messages from the alter ego Persy_PCP, who claimed to divide his life between two countries. In November 2025 he wrote: “My whole country is racist and wants people like me dead.” BulkDMT shared in September 2025 a comment about farmers in South Africa. Cyberscoop reported in June 2026 that Google had traced TeamPCP connections to South Africa.

SpyCloud found that the email [email protected] appears in the registration of the account ChristmasSnow on the Raidforums community in 2022. Almost all IP addresses used to access that account came from ISPs in Perth, Australia. KrebsOnSecurity analyzed the Perth IPs in DomainTools passive DNS records and identified the address 211.27.196.111, used for several years as a private file server by a Perth family with the surname Thomson. At the same address, Synology and QNAP hosts were active between 2022 and 2025. A search for “joshuathomson39” on Constella Intelligence showed an account at the shipping company kwe.com registered to Joshua Thomson of Perth. The platform Epieos linked the phone number to a Facebook profile of Josh Thomson, which indicates a family originally from Pietermaritzburg, South Africa, residing in Cottesloe, a coastal suburb of Perth.

What Companies Can Do

No details have been released about specific CVEs or entries in CISA’s KEV catalog, because the operation concerns a criminal group as a whole, not a single vulnerability. However, affected or potentially exposed organizations should adopt standard software supply chain defense measures:

  • Verify the integrity of open source packages before installation by comparing hashes and signatures with official repositories.
  • Protect developer credentials with multi-factor authentication and least privilege.
  • Monitor dependencies and build pipelines to detect unauthorized changes.
  • Check access to repositories and cloud services, looking for exposed keys or lateral movement.
  • Inspect logs for anomalous activity related to the IPs or domains mentioned in the investigation.

The exact versions of the compromised products have not been disclosed, but anyone using LiteLLM or maintaining repositories on GitHub should review commit history and service keys.

The arrest of the two alleged members does not guarantee the end of TeamPCP. The community structure and the availability of the Shai-Hulud code leave open risks of new campaigns. The investigations by the Australian Federal Police and international partners continue.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicscybercrimearrestopen sourcesupply chain attackTeamPCPmalwareAustralian Federal Police
Back to home