Product1 distinct publisher3 min readPublished
Australian Federal Police arrested two men over malicious code the agency estimates reached more than 1,000 organisations. What identified the alleged leader was a screen name he kept using on other platforms.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The developer who pulled a utility off GitHub last year was not being careless. That is where the utilities are. TeamPCP hosted its own tools there too, under an account linked to the alias DeadCatx3 [3], and everything the Australian Federal Police counted afterwards came out the far end of that ordinary path.
Divide the credential and data totals by the AFP's own count of affected organisations and the average victim contributed roughly 500 credentials [16] and roughly 300 megabytes of data [17]. No real victim sits on an average; one gives up a laptop keychain and the next gives up a CI secret store. But the per-organisation figure is the one a security lead can hold against their own environment, and it reads closer to a developer's stored logins than to a customer database.
According to Flare, the DeadCatx3 handle from GitHub also existed on HackerOne, where an account registered in June 2025 listed its owner's full name [5][6]. "The account in question had the name Ruben Thomson connected to it. It can't be that easy, can it?" the firm wrote [7]. Flare then matched a cartoon cat in a hoodie, used as the avatar on a Steam account traced to Thomson, with the profile picture in a screenshot of TeamPCP's Telegram account, and said it was highly confident he led the group [8][9]. Flare also described TeamPCP as "loud by choice", posting on Telegram and X until the account was shut down [10], and said a group talking that much under that many aliases "hands you the first thread to pull" [11].
None of that is a security product. The published trail runs through a bug bounty profile and a games-platform avatar, and no scanner or registry control appears anywhere in it [18]. That is the distance between what dependency tooling is sold on, which is catching the payload, and what actually produced a name here, which was a 21-year-old's attachment to a handle [4][15].
Two questions sort most of the intake problem, and they work on artifacts already installed rather than on the next procurement cycle. Does this thing run on a machine holding long-lived credentials, or only inside a build that gets thrown away? And does anything in the pipeline record which human account published the exact version that landed? Developer tooling usually answers yes to the first and nothing at all to the second, and the AFP's totals describe what that square of the grid pays out when the publisher turns out to be hostile. The reporting names neither the packages nor the victim organisations [19], so nobody gets told they were in the 1,000; the inventory that answers the question covers the laptops and build runners where developers keep their tokens.
Ranked by verification strength, evidence, and original report placement.
On Thursday, law enforcement arrested two men in Australia who are allegedly part of TeamPCP, a hacking gang that has been spreading malware through open-source software tools.
The Australian Federal Police said it is estimated the malicious code potentially compromised more than 1,000 organisations globally, enabling the theft of more than 500,000 credentials and the exfiltration of at least 300 gigabytes of data.
TeamPCP has been linked to the alias DeadCatx3 via an account on the software development platform GitHub, which the group used to host its tools.
One of the reported suspects, 21-year-old Ruben Thomson, was not hard to identify because of his association with the screen name DeadCatx3, according to a report by cybersecurity provider Flare.
Flare checked whether the DeadCatx3 handle was registered on other platforms and found it on HackerOne, a bug bounty platform security researchers use to submit software vulnerabilities.
A HackerOne user registered an account with the DeadCatx3 handle in June 2025 and also listed their full name on the profile.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
A repo compromise found in week four outlives GitHub's seven-day Git event log1 distinct publisher
product
The AI-wrote-it claim died in eight hours. The Actions injection pattern did not.1 distinct publisher
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
build
Claude Code's new default is a confession: the approval prompt was never a control1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-outlet retelling of a vendor report plus an official statement
Load-bearing facts are attributable: an AFP statement is quoted directly for impact and charges, and Flare's report is quoted for each attribution step, with KrebsOnSecurity cited as independent prior reporting. But the cluster has exactly one publisher and no primary documents - no charge sheet, no AFP release link, no Flare report excerpt beyond quotes - and the reporting names no affected package, repository or victim, so the scope claims cannot be independently checked.
Real-world incident with arrests and an official scope estimate
This is not a technology-uptake story, so adoption is read as demonstrated real-world consequence. That consequence is concrete at the enforcement end - two named suspects arrested, 14 charges, scheduled court appearance - and quantified at the victim end only by an AFP estimate covering 1,000-plus unnamed organisations. Nothing in the reporting shows victim notification, incident response or package removal, which keeps this mid-range rather than high.
Framing overstates the causal link between handle reuse and arrest
The verifiable facts - the handle pivot, the avatar match, the AFP figures, the arrests - are reported soberly and with attribution. Overstatement sits in the causal frame: headline and lede assert the reused screen name 'likely helped investigators catch him,' while no law-enforcement account of investigative method appears, and the underlying vendor report is an after-the-fact OSINT reconstruction with commercial value to its author. The gap is modest, not severe, because the numbers themselves are officially sourced and hedged.
Vendor attribution report and enforcement announcement both benefit from amplification
Two disclosing parties have visible interests. Flare is identified in the source as a cybersecurity provider whose 'new report' supplies the entire investigative narrative and demonstrates its OSINT capability; the AFP is announcing an enforcement success and supplies the impact figures that make the case newsworthy. Neither interest is concealed - the source labels Flare a vendor - but the reporting relies on both parties' framing without independent verification.
Moderate: specific attributed facts, single publisher, unverified scope
Confidence is moderate. The identity-attribution and enforcement facts are specific, internally consistent and echoed by cited independent reporting from KrebsOnSecurity, which raises trust in the core narrative. It is held down by one-publisher coverage, sole reliance on vendor and agency framing, absent primary documents, unnamed packages and victims, and a headline causal claim that no cited investigator confirms.