- Arrests and Charges: Australian authorities arrested Ruben Ian Thomson and Louis Michael Gaebler for their roles in the TeamPCP cyber group, which allegedly compromised over 1,000 organizations.
- Technical Exploitation: The group utilized a self-propagating worm named Shai-Hulud to infiltrate supply chains via GitHub Actions, NPM, and PyPI, stealing 300 gigabytes of sensitive data.
Joint Operation Leads to Arrest of Alleged Syndicate Members
Australian authorities have dismantled a global cybercrime network following a 15-month investigation. On August 26, 2024, a joint operation involving the AFP Cyber Command, the Western Australia Police Force (WAPF), and the U.S. Federal Bureau of Investigation (FBI) led to the arrest of two men. Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, were charged for their suspected involvement with the group known as TeamPCP.
This group is accused of orchestrating one of the most extensive software supply-chain campaigns observed to date. Throughout the investigation, Australia arrests were finalized after the group allegedly breached more than 1,000 organizations worldwide. Investigators allege that the suspects were key members of the group and received cryptocurrency payments for their illicit activities.
Advanced Supply-Chain Infiltration Tactics
The TeamPCP group specialized in injecting malicious code into popular open-source repositories and developer tools, specifically targeting platforms like NPM, PyPI, and GitHub Actions. To scale their efforts, the hackers deployed a self-propagating worm dubbed Shai-Hulud, along with a “Mini” variant, designed to automate credential theft across CI/CD pipelines.
The group exploited a vulnerability in the pull_request_target workflow trigger within GitHub Actions, allowing them to exfiltrate service account tokens and gain unauthorized write access to repositories. While many hackers rely on social engineering lures, TeamPCP focused on the underlying infrastructure of software development. Targeted tools included Aqua Security’s Trivy scanner, Checkmarx’s KICS, and the AI gateway LiteLLM.
Massive Data Exfiltration and Financial Damage
The scope of the group’s activities is extensive, with the Australian Federal Police estimating global remediation costs in the hundreds of millions of dollars. This incident mirrors other major incidents that require massive recovery efforts. TeamPCP is alleged to have stolen at least 500,000 corporate credentials and exfiltrated more than 300 gigabytes of data from victims.
Ruben Ian Thomson of Cottesloe faces eight charges, including unauthorized modification of data and dealing with proceeds of crime. He is also charged with failing to comply with a section 3LA order regarding device passwords. Louis Michael Gaebler of Mandurah faces six charges, including possessing data with intent to commit a computer offense.
Security Recommendations and Remediation
Following the arrests, the FBI issued a FLASH advisory to assist impacted organizations. The agency recommends that all companies affected during the breach period immediately rotate their CI/CD secrets, publishing tokens, and cloud credentials to mitigate further unauthorized access resulting from the stolen credentials.
