Australia charges two men over TeamPCP supply-chain attacks
This digest was compiled by AI from multiple sources — links to the originals are below.

Australian Federal Police charged two Western Australian men, aged 21 and 23, over their alleged role in the TeamPCP cybercrime syndicate. The pair appeared in Perth Magistrates Court on August 27, 2026, facing 14 combined offences. The group's malicious code potentially compromised over 1,000 organizations worldwide.
Key Facts
- Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27, 2026, charged with 14 combined offences.
- TeamPCP's malicious code potentially compromised over 1,000 organizations worldwide, enabling theft of half a million credentials and exfiltration of at least 300GB of data.
- The group's attacks impacted Trivy, LiteLLM, Telnyx, SAP, and TanStack packages, and breached the European Commission, Mistral AI, OpenAI, and GitHub.
- TeamPCP launched a contest in May 2026 offering $1,000 in virtual currency for the largest supply chain operation using the Shai-Hulud worm's code.
- The FBI advised organizations to rotate all CI/CD secrets, publishing tokens, and cloud credentials accessible during exposure windows.
Arrests and Charges
Australian Federal Police charged two Western Australian men, Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, with a combined total of 14 offences. The pair appeared in Perth Magistrates Court on August 27, 2026, a day after search warrants were executed at properties in Cottesloe, Hamilton Hill, and Mandurah. Police allege the two men were principal participants in the syndicate and received payments in cryptocurrency, the value of which is still under investigation. The AFP described the group as a 'sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.'
TeamPCP Operations
TeamPCP emerged in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. The group compromised corporate cloud environments using a self-propagating worm dubbed Shai-Hulud, which added malicious code to open source programs maintained by developers whose credentials at GitHub or NPM were phished or stolen. High-profile attacks attributed to TeamPCP have impacted Trivy, LiteLLM, Telnyx, SAP, and TanStack packages, while the group has also breached the European Commission, Mistral AI, OpenAI, and GitHub. Rather than a cohesive group, the malicious activity is believed to have been carried out by a loose-knit collective of threat actors who frequent the same hacking forums, Discord servers, and Telegram channels.
Impact and Response
According to the AFP, FBI, and Western Australia Police, malicious code distributed by TeamPCP has potentially compromised over a thousand organizations worldwide, enabling the theft of half a million credentials and the exfiltration of at least 300GB of data. The FBI said in a July 2 advisory that organizations impacted by the campaign should treat exfiltrated data and credentials as a persistent risk, since affiliated threat actors are 'likely to weaponize them long after the initial compromise.' FBI Cyber Division Assistant Director Brett E. Leatherman said the two men are allegedly members of TeamPCP, whose malicious code 'potentially compromised more than a thousand organizations worldwide.' The FBI advised rotating all continuous integration and continuous delivery (CI/CD) secrets, publishing tokens, and cloud credentials accessible during the exposure windows.
3 sources
Australia charges two men over TeamPCP supply-chain attacks



