Video summary
The video details the dramatic deanonymization of Team PCP, a notorious hacker group responsible for poisoning five major software ecosystems in early 2026. The investigation began after a colleague leaked information about an impending exposé involving cats, which turned out to be a reference to the group's online persona featuring a cat profile picture. For years, Team PCP operated as a loud and boastful crew of teenagers and young adults who exploited misconfigured cloud services like Docker APIs and Kubernetes control planes to build massive botnets. Their activities evolved from opportunistic crypto-mining and data extortion into sophisticated supply chain attacks, most notably compromising the Trivy vulnerability scanner and subsequently infecting the widely used Light LLM package, which was downloaded nearly 100 million times a month.
The core of the investigation relied on Open Source Intelligence (OSINT) techniques to trace the group's digital footprint across various platforms. Investigators identified several aliases associated with the group, including DeadCatX3, Shell Force, and Percy_PCP, which were used to taunt victims and brag about their exploits on social media and Telegram channels. By utilizing advanced threat intelligence tools, researchers were able to link these usernames to a network of accounts spanning Instagram, Reddit, HackerOne, and Hugging Face. A crucial breakthrough occurred when investigators searched for leaked credentials tied to the email address surfinup8@gmail.com, which led them to a TikTok account belonging to Yolo Solo 17. This account contained a video showcasing a Steam profile that had received a VAC ban, providing a unique visual clue in the form of a specific profile picture.
The final confirmation came from connecting this visual evidence back to the group's communication channels and real-world identity. Investigators found that the same unique profile picture appeared on a Telegram chat associated with the alias pcp.sh, directly linking the Steam account to the hacker group's leadership. Further digging revealed that the username Yolo Solo 17 belonged to Reuben Thompson, a resident of Perth, Australia, whose HackerOne profile also listed his real name. This convergence of circumstantial evidence, including the timeline of the Steam ban and the specific imagery, provided law enforcement with high-confidence proof of identity, leading to the arrest of Reuben Thompson. The case serves as a stark reminder that even the most elusive cybercriminals who seek attention through memes and jokes can be unmasked when their digital breadcrumbs are carefully followed, ultimately bringing an end to one of the year's most significant supply chain incidents.
Read the full video transcript
Last night I got an unexpected message.
Someone I work with had said, "Hey John,
just wanted to give you a heads-up that
we have something cooking over here that
I'm going to try and send you under
embargo later today. Our biggest story
yet." And I thought, "Ooh, that sounds
ominous. Can I get a hint?" And they
responded, "Something about cats." Um,
cats? Later they messaged me again, "Hey
John,
here it is. We have deanonymized Team
PCP." And I was just doom-scrolling on
my couch just like, "What?" So I'm
responding, "Holy
That's a huge intel drop." And the last
thing they say to me is "Thanks. If you
want to cover it, you can recreate the
whole investigation." So that's what
we're doing today, everybody. We are
going to OSINT investigate the leader of
one of the most notorious hacker groups
in 2026. Unmasking Team PCP, king of
software supply chains, a walk-through
of the process of deanonymization by
Flare's emerging threats team.
All right, that's Flare. Look, this
video is not technically sponsored, but
Flare is an incredible channel partner,
and my goodness gracious, they have such
a cool story to tell here. I'm just so
ecstatic that they are in the industry
doing incredible things, so let's dive
in. For 5 days in March 2026, a single
stolen token let one group poison five
software ecosystems, including a package
downloaded 95 million times a month. The
attack started with a misconfigured
GitHub workflow and ended with
backdoored code sitting inside CI/CD
pipelines around the world. Oh, here's
where it gets good. Now, the person
behind this attack has been arrested.
The group this actor was in, Team PCP,
is a crew that started in late 2025
running opportunistic cloud exploits,
and then pivoted in early 2026 to
attacking the software supply chain
itself. For folks who don't know, Team
PCP, who has an online profile picture
of this cat,
has hacked Tan Stack, the GitHub
internal breach, Trivy, Light LLM,
Checkmarks, Telnix, so many different
Python packages in the Python package
ecosystem, NPM. They did the Shai-Hulud
attack. You know, the one about Dune?
Anyway, Flare's Emerging Threats Team
wanted to share examples of some of the
techniques that can be used to unmask
the operator behind Team PCP. So, we'll
use the Flare platform to trace a single
alias across the accounts, credentials,
and infrastructure that connected back
to a real identity. There were other
individual investigations on this topic,
including one by Brian Krebs, a very
well-known cybersecurity reporter. So,
we will walk through who Team PCP is and
share the process of deanonymizing
threat actors. Now, I had a recent
YouTube video covering Team PCP and some
of their antics, and we talked about
some of their maintained Telegram
channels, how they have this Twitter or
X I'm just going to call it Twitter, all
this online personas, and how they would
taunt victims and even gave a press
interview. They were always kind of
bragadocio, pretty chest-thumpy, like
throwing the flag in the ground, "Oh, I
hacked that." kind of thing. High school
drama stuff that I always poopoo. But,
it was that same appetite for credit
that amplified their campaigns and
produced the reused handles, avatars,
and infrastructure references that
essentially got them doxed. So, for
background context, let me add a little
bit more of Team PCP history. At the end
of last year in 2025, when they were
just an opportunistic cloud exploitation
crew, they would have an automated
scanner sweep the entire internet for
exposed APIs. Things like Docker APIs,
Kubernetes control planes that were just
left wide open, Ray dashboards, Redis
instances, anything that they could
spray and pray, cast a wide net, and
then get an implant, compromise, and
own. They would then take that
compromised infrastructure and basically
turn it into a botnet. They deploy
containers on each infected host, and
that would then become another scanner
and proxy node, and self-propagate
further infection. Now, you know I'm a
fanboy, Flare's always doing super cool
stuff. Their honeypots recorded this
activity first hand, and they
fingerprinted 185 Docker compromises in
just one campaign. With most
cybercriminals, money is the motivator,
and revenue came from three sources.
There was XMRig, just crypto miners, and
they'd rent their proxy server to bring
in more cash. They would leak or sell
stolen data for extortion money, and
then they brought the React to Shell
campaign against Next.js applications.
Apparently, their own control server
dashboard had almost 60,000 servers
compromised in under 48 hours. Now, as
much more of us know, in 2026, Team PCP
shifted to target the software supply
chain. They would go after tools and
packages and libraries and things that
other applications would depend on, and
things that companies trust. In
February, Team PCP exploited a
misconfigured GitHub Actions workflow in
Aqua Security's Trivy, which is one of
the world's most widely deployed
open-source vulnerability scanners. And
they stole a service account token. Aqua
Security rotated credentials, but they
missed some, and Team PCP, the hackers,
still had access. So, later on in March,
they published a malicious Trivy release
across every distribution channel all at
once. That poisoned thousands of CI/CD
pipelines with credential stealing
malware. And being a supply chain
threat, that thing trickled down like
dominoes. The AI proxy library light LLM
ran that poisoned Trivy inside their own
build pipeline, so the attackers then
harvested their PyPI publishing token,
so they could release two backdoored
light LLM releases. Now, light LLM, that
software package, brings in about
roughly 95 million downloads a month.
So, from just one token, the threat
actors hacked five entire software
ecosystems across five days. But now,
let's get into the OSINT. Team PCP
aliases. The group operates behind a web
of names, which was important to the
investigation, and they'll get further
into it. The core identity is Team PCP,
but its work shows up under the name PCP
Cat. That was part of the first name
campaign. Shell Force is its leak
publication persona, and DeadCatX3
is a GitHub account hosting tooling, as
well as Percy_PCP
and PCPsh, which were earlier Telegram
handles. The group is loud by choice.
They're active in Telegram channels,
they post on X under PCP Cats now
deleted, and they taunt everybody.
They're jokesters, they're jesters,
they're la ha ha he he hackers. And now
they're arrested. They had an interview
with Forbes, and TPCP themselves said,
"Oh, the group is a loose-knit group of
teenagers and young adults who couldn't
find paying work, so they turned to
cybercrime." Now, Flare's threat flow
solution found that Team PCP used these
usernames. One of the most curious was
DeadCatX3.
That became the anchor for the whole
investigation. So, Flare said they put
the name DeadCatX3 into
osint.industries, and we can do the very
same. I'm online here, we'll toggle this
to the username, want to look up
DeadCatX3. We'll agree to the terms, and
search. All right, scanning through a
couple of these, looks like it is
finding a good many hits, and okay, the
search has fully completed now, and we
have a relationship graph and a lot of
their online accounts. Instagram,
HackerOne, we'll dive into that. I don't
know about the one at the bottom there.
Ooh, a nice little Minecraft character.
Okay, sorry. Reddit, Scratch, Roblox,
nice. Telegram, oh, hugging face, and
hacker one. Oh, no, don't scroll further
down. Interesting, the name here is
Reuben Thompson. Let me view account
here. Yep, deadcatx3 and Reuben
Thompson. I do want to see the hugging
face one, too. RT, maybe initials for
Reuben Thompson. And look at this,
masscan.cloud, what is that? Uh, oh,
Flare says this domain, masscan.cloud,
was used as the C2 or command and
control during the Minishat worm
infection in May. Look here, they have
a, uh, write-up and I think they cover
it down below. Oh, look, look, look,
there is the, uh, Telegram percy_pcp
alias and, uh, the other channel here.
Where was the masscan.cloud? Oh, man,
here's the react scanner, some of their
docker configs, XMRig, the crypto miner.
Where is the C2? Cube control, come on.
Oh, I'm scrolling for a while, guys.
Okay, this is when they were in their,
uh, Telegram channel. Holy cow.
Oh, there's a GitHub. Yeah, deadcat is,
uh, pretty apt naming right now, huh?
Look at it, it's right there in, uh,
GitHub, too. And, okay, masscan.cloud,
right in there. Geez. Okay, so, Reuben
Thompson, it can't be that easy though,
right? We got to dig in a bit more, find
some more concrete evidence, right? But
now we have a name, a potential name.
So, let's bring that right back in to
OSINT Industries.
And what could we track down for that?
All right, that scan is thinking
Australia.
Um, Reuben Thompson, I'm curious if we
can get another emails, but, oh, uh,
usernames, surfinup8b4f0.
Okay. Well, I'm not seeing a ton of, uh,
emails or things to like kind of pivot
off of. What if we honed in on
Australia? Like, is it dumb to just
simply search for Reuben Thompson,
Australia?
Um, is there a LinkedIn page?
Oh, doesn't exist. Look, take that for
what you will, all right? Now, I'm speed
running just a little bit because I know
the investigation did lead to that
Surfin Up 8 username, and it turns out
it's tied to a Gmail address. Just super
simple, surfinup8@gmail.com.
Now, a wildly interesting thing you can
do is kind of take a lot of the same
threats that threat actors throw at us
and kind of wonder, "Ooh, is there any
insight on them?" And what I mean by
that is taking a look at info-stealer
malware logs. Were any of the hackers
ever hacked themselves? In all of the
data breaches and leaks across the
history of the internet, could we track
down that Gmail address and maybe find
even passwords to pivot off of? So, what
we'll do is use the Flare credential
browser. Ooh, they have a nice new
interface. Let me take a second to dig
in the platform, and this is really
cool. Oh, sorry, don't show my passwords
or people with my name that have been
caught in a breach. And this is really
cool because we're actually being able
to utilize this for a real cyber crime
investigation. This is the awesome power
of Flare. Let me search for
surfinup8@gmail.com
and passwords. This could help us prove
some definitive use of online accounts,
but now we're wondering, "Okay, what
other accounts are tied to this email?"
Now, the Flare research team could take
some of these leaked passwords and take
some of these email addresses and keep
hunting. And they found a TikTok account
that's associated with the username Yolo
Solo 17. Now, I happen to be on this
TikTok account's page, and it has only
one video of what looks like a Steam
account, Yolo CrownZ,
and a lot of uh trading things here with
uh scammer? I don't know. But, this is
weird, right? I mean, I I guess there's
a ban. You can see there's one VAC ban
account on record. Is this Steam account
somehow affiliated with Team PCP? The
profile picture is a cat, but I don't
know if it counts. So, this is a weird
finding, right? And I don't know how
much more there is to go off of of a
TikTok video of a Steam account, but if
we're getting scrappy and creative, I
mean, could we be looking for other
Steam friends or folks they play games
with? You could use the context of
Australia and some of the other
information that's bubbled up in the
investigation and Flare did it. And I
want to pull up the picture here cuz
it's kind of wild. Train Simulator
Classic, a little bit of VRChat in
Perth, Australia. And down below, we
have Ellis. I can't really quite make
out that profile picture, but if you
look up their Steam account, they have a
VAC ban on the exact same day that this
TikTok account, Yolo Solo 17, Reuben
Thompson, posts this video of a Steam
account, March 7th, 2017. Here is the
Steam account. Little bit of a higher
quality picture for the profile picture
you for you to see. A lot of time in
VRChat, but here is the VAC list or VAC
list entry. One VAC ban on record,
September 13th, 2016. Now, that's not
March 7th, 2017, but look closely here.
What is that? 175 days since that ban?
Timeline kind of lines up. And this
profile picture is actually kind of
unique. We could hone in on that. Even
if we did a super simple little Google
reverse image search, there's nothing
really else there other than that stuff.
Okay, I we don't need to record this
part. So, at this point, we have an
interesting new breadcrumb and puzzle
piece. That profile picture, right? It
feels unique, but we couldn't find
anywhere else to run with it based off
of just a Google image reverse search,
but we've been building this mind map of
the investigation and we know all these
different aliases and identities that
team PCP uses. So, what if we went back
to the drawing board and kept taking a
look at some of those other Telegram
handles? So, no tricks up my sleeve
here. What I want to do is hop over to
the events tab on Flare and search for
I'm going to unselect everything and
just focus in on chats or Telegram chats
and I want to search for just the
username, right? pcp.sh
Can we find any occurrences of chatter
communication with that account across
the history of their Telegram? And we
have a couple hits from Maya the Fox and
they say, "Just run this little EXE and
boom." What is that EXE?
I don't think I have to tell you.
It is the
same Steam profile picture. That is some
pretty high confidence.
That's the guy. That's the cat. Team PCP
ringleader, literally the Telegram
account that they've been chitchatting
chirping with Cybercrime on is the exact
same as the Steam profile picture tied
to the accounts, all bringing us back to
the name Reuben Thompson. I know we ran
a little all over the map. I know this
is a bit of an abbreviated showcase just
to explain the whole investigation in
the snapshot of a YouTube video.
Obviously, there were so many more hey
rabbit holes and things to dig into, but
do you see the line? This all chains
together and I think it's no longer
circumstantial evidence to like high
confidence. Hacker One account has their
real name Reuben Thompson. That
deadcatx3 handle is how you track down
the Hacker One account and the Hugging
Face domain, which has their C2 domain
from the mini Shai Halud attack. That,
of course, proves their Cybercrime
shenanigans. They're bragging about it,
chest thumping over on Telegram, but the
same real name leads to a TikTok account
where he has personally and voluntarily
uploaded a video of a Steam account that
got banned on the day that all has these
puzzle pieces fall into place to find
the exact same profile picture pointing
definitely. I'm thinking that's the Team
PCP leader. Reuben Thompson based out of
Perth, Australia operating behind the
identity deadcat x3. That single alias
led to a verifiable person's identity
and that was confirmed by law
enforcement's arrest. Holy smokes
everybody. I don't know if you had the
same reaction that I do, but I just
think that's a wild ride. Team PCP that
made headlines for the entire year and
that story unraveled. That identity
unraveled. And the whole thing Team PCP
was all about, you know, the hee hee ha
ha's, the cats and the jokes, calling
cards and logs, oh PCP was here. That
cybercriminal wanted an audience and
they got one. The Team PCP hacks and
exploits and escapades were some of the
most consequential supply chain
incidents throughout the whole year. But
that same person who wanted all this
attention and spotlight for the memes,
for the lols, and the kitty cat profile
picture. Turns out there was another
unique kitty cat profile picture that
they left on a Steam profile for a
decade just waiting for someone to find
it and law enforcement confirmed the
investigation and their identity and it
led to their arrest.
Damn everybody. Look, you know, Flare is
a channel partner and I think they are
just super cool. They have incredible
threat intelligence. They do just so
many cool things and it's just so
it makes me feel so good to have the
partners in the industry that do real
work, that move the needle, that
actually make such a cool difference in
the security industry and raise up
the whole security posture of everyone
to take down hackers and cyber
criminals. Man, it's just so cool. I
I stayed up really late to try to get
this video out the door because I know
this was an under embargo story, but
huge congrats, guys. What a win for the
industry thanks to you. Please do give
Flare some love with the link below in
the video description. You know the
drill, like, comment, subscribe. What an
awesome story to tell.