The Australian Federal Police has charged two Western Australian men over their alleged roles in the TeamPCP hacking group, the syndicate blamed for a string of open-source supply chain attacks that began in late 2025.
Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on 27 August facing a combined 14 offences. In a statement, the AFP described the pair as part of “a sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.” The AFP statement did not name either man; that came from court records once the case reached Perth.
Inside the TeamPCP hacking group’s alleged campaign
TeamPCP first surfaced in late 2025, embedding malicious code into hundreds of open-source packages and then extorting the businesses that depended on them. Its most damaging campaign landed in March 2026, when the group compromised the open-source security scanners Trivy and Checkmarx KICS, along with the AI gateway LiteLLM. All three are tools engineering and security teams use specifically to catch malicious code before it reaches production, which made the compromise more than an ordinary poisoned package: it hit the layer meant to prevent exactly this kind of attack.
A cross-border case
SecurityWeek reported that Australian and US authorities worked together to identify and charge the pair, and that both face many years in prison if convicted. That cooperation reflects how supply chain attacks tend to play out: the poisoned code, the victims and the people running the operation are rarely in the same country, so a single national police force is seldom enough to build a case. It is also the latest in a run of cross-border enforcement actions against hacking operations, following moves like the DOJ’s seizure of domains linked to Chinese state-sponsored hackers.
How the identification came together
Krebs on Security had already identified Thomson by name back in June, two months before the arrests, and had been in contact with him since. Krebs traced a series of missteps the alleged TeamPCP leader left behind, including a GitHub account, since archived, that ties back to the identity Krebs had already reported. Krebs also interviewed someone describing themselves as TeamPCP’s spokesperson, a separate thread from the account that reportedly exposed the leader.
What to watch
Neither Gaebler nor Thomson has entered a plea, and the AFP has not said whether it believes anyone else was involved in the March compromise of Trivy, Checkmarx KICS and LiteLLM. The spokesperson Krebs interviewed was speaking independently of the two men now charged, which leaves open whether more of TeamPCP is still operating while the Perth case proceeds.








