Submind YouTube summaries
Thumbnail for GitHub Hacker EXPOSED BY HIS CAT

GitHub Hacker EXPOSED BY HIS CAT

Watch on YouTube

Video summary

The video details the dramatic deanonymization of Team PCP, a notorious hacker group responsible for poisoning five major software ecosystems in early 2026. The investigation began after a colleague leaked information about an impending exposé involving cats, which turned out to be a reference to the group's online persona featuring a cat profile picture. For years, Team PCP operated as a loud and boastful crew of teenagers and young adults who exploited misconfigured cloud services like Docker APIs and Kubernetes control planes to build massive botnets. Their activities evolved from opportunistic crypto-mining and data extortion into sophisticated supply chain attacks, most notably compromising the Trivy vulnerability scanner and subsequently infecting the widely used Light LLM package, which was downloaded nearly 100 million times a month. The core of the investigation relied on Open Source Intelligence (OSINT) techniques to trace the group's digital footprint across various platforms. Investigators identified several aliases associated with the group, including DeadCatX3, Shell Force, and Percy_PCP, which were used to taunt victims and brag about their exploits on social media and Telegram channels. By utilizing advanced threat intelligence tools, researchers were able to link these usernames to a network of accounts spanning Instagram, Reddit, HackerOne, and Hugging Face. A crucial breakthrough occurred when investigators searched for leaked credentials tied to the email address surfinup8@gmail.com, which led them to a TikTok account belonging to Yolo Solo 17. This account contained a video showcasing a Steam profile that had received a VAC ban, providing a unique visual clue in the form of a specific profile picture. The final confirmation came from connecting this visual evidence back to the group's communication channels and real-world identity. Investigators found that the same unique profile picture appeared on a Telegram chat associated with the alias pcp.sh, directly linking the Steam account to the hacker group's leadership. Further digging revealed that the username Yolo Solo 17 belonged to Reuben Thompson, a resident of Perth, Australia, whose HackerOne profile also listed his real name. This convergence of circumstantial evidence, including the timeline of the Steam ban and the specific imagery, provided law enforcement with high-confidence proof of identity, leading to the arrest of Reuben Thompson. The case serves as a stark reminder that even the most elusive cybercriminals who seek attention through memes and jokes can be unmasked when their digital breadcrumbs are carefully followed, ultimately bringing an end to one of the year's most significant supply chain incidents.
Read the full video transcript
Last night I got an unexpected message. Someone I work with had said, "Hey John, just wanted to give you a heads-up that we have something cooking over here that I'm going to try and send you under embargo later today. Our biggest story yet." And I thought, "Ooh, that sounds ominous. Can I get a hint?" And they responded, "Something about cats." Um, cats? Later they messaged me again, "Hey John, here it is. We have deanonymized Team PCP." And I was just doom-scrolling on my couch just like, "What?" So I'm responding, "Holy That's a huge intel drop." And the last thing they say to me is "Thanks. If you want to cover it, you can recreate the whole investigation." So that's what we're doing today, everybody. We are going to OSINT investigate the leader of one of the most notorious hacker groups in 2026. Unmasking Team PCP, king of software supply chains, a walk-through of the process of deanonymization by Flare's emerging threats team. All right, that's Flare. Look, this video is not technically sponsored, but Flare is an incredible channel partner, and my goodness gracious, they have such a cool story to tell here. I'm just so ecstatic that they are in the industry doing incredible things, so let's dive in. For 5 days in March 2026, a single stolen token let one group poison five software ecosystems, including a package downloaded 95 million times a month. The attack started with a misconfigured GitHub workflow and ended with backdoored code sitting inside CI/CD pipelines around the world. Oh, here's where it gets good. Now, the person behind this attack has been arrested. The group this actor was in, Team PCP, is a crew that started in late 2025 running opportunistic cloud exploits, and then pivoted in early 2026 to attacking the software supply chain itself. For folks who don't know, Team PCP, who has an online profile picture of this cat, has hacked Tan Stack, the GitHub internal breach, Trivy, Light LLM, Checkmarks, Telnix, so many different Python packages in the Python package ecosystem, NPM. They did the Shai-Hulud attack. You know, the one about Dune? Anyway, Flare's Emerging Threats Team wanted to share examples of some of the techniques that can be used to unmask the operator behind Team PCP. So, we'll use the Flare platform to trace a single alias across the accounts, credentials, and infrastructure that connected back to a real identity. There were other individual investigations on this topic, including one by Brian Krebs, a very well-known cybersecurity reporter. So, we will walk through who Team PCP is and share the process of deanonymizing threat actors. Now, I had a recent YouTube video covering Team PCP and some of their antics, and we talked about some of their maintained Telegram channels, how they have this Twitter or X I'm just going to call it Twitter, all this online personas, and how they would taunt victims and even gave a press interview. They were always kind of bragadocio, pretty chest-thumpy, like throwing the flag in the ground, "Oh, I hacked that." kind of thing. High school drama stuff that I always poopoo. But, it was that same appetite for credit that amplified their campaigns and produced the reused handles, avatars, and infrastructure references that essentially got them doxed. So, for background context, let me add a little bit more of Team PCP history. At the end of last year in 2025, when they were just an opportunistic cloud exploitation crew, they would have an automated scanner sweep the entire internet for exposed APIs. Things like Docker APIs, Kubernetes control planes that were just left wide open, Ray dashboards, Redis instances, anything that they could spray and pray, cast a wide net, and then get an implant, compromise, and own. They would then take that compromised infrastructure and basically turn it into a botnet. They deploy containers on each infected host, and that would then become another scanner and proxy node, and self-propagate further infection. Now, you know I'm a fanboy, Flare's always doing super cool stuff. Their honeypots recorded this activity first hand, and they fingerprinted 185 Docker compromises in just one campaign. With most cybercriminals, money is the motivator, and revenue came from three sources. There was XMRig, just crypto miners, and they'd rent their proxy server to bring in more cash. They would leak or sell stolen data for extortion money, and then they brought the React to Shell campaign against Next.js applications. Apparently, their own control server dashboard had almost 60,000 servers compromised in under 48 hours. Now, as much more of us know, in 2026, Team PCP shifted to target the software supply chain. They would go after tools and packages and libraries and things that other applications would depend on, and things that companies trust. In February, Team PCP exploited a misconfigured GitHub Actions workflow in Aqua Security's Trivy, which is one of the world's most widely deployed open-source vulnerability scanners. And they stole a service account token. Aqua Security rotated credentials, but they missed some, and Team PCP, the hackers, still had access. So, later on in March, they published a malicious Trivy release across every distribution channel all at once. That poisoned thousands of CI/CD pipelines with credential stealing malware. And being a supply chain threat, that thing trickled down like dominoes. The AI proxy library light LLM ran that poisoned Trivy inside their own build pipeline, so the attackers then harvested their PyPI publishing token, so they could release two backdoored light LLM releases. Now, light LLM, that software package, brings in about roughly 95 million downloads a month. So, from just one token, the threat actors hacked five entire software ecosystems across five days. But now, let's get into the OSINT. Team PCP aliases. The group operates behind a web of names, which was important to the investigation, and they'll get further into it. The core identity is Team PCP, but its work shows up under the name PCP Cat. That was part of the first name campaign. Shell Force is its leak publication persona, and DeadCatX3 is a GitHub account hosting tooling, as well as Percy_PCP and PCPsh, which were earlier Telegram handles. The group is loud by choice. They're active in Telegram channels, they post on X under PCP Cats now deleted, and they taunt everybody. They're jokesters, they're jesters, they're la ha ha he he hackers. And now they're arrested. They had an interview with Forbes, and TPCP themselves said, "Oh, the group is a loose-knit group of teenagers and young adults who couldn't find paying work, so they turned to cybercrime." Now, Flare's threat flow solution found that Team PCP used these usernames. One of the most curious was DeadCatX3. That became the anchor for the whole investigation. So, Flare said they put the name DeadCatX3 into osint.industries, and we can do the very same. I'm online here, we'll toggle this to the username, want to look up DeadCatX3. We'll agree to the terms, and search. All right, scanning through a couple of these, looks like it is finding a good many hits, and okay, the search has fully completed now, and we have a relationship graph and a lot of their online accounts. Instagram, HackerOne, we'll dive into that. I don't know about the one at the bottom there. Ooh, a nice little Minecraft character. Okay, sorry. Reddit, Scratch, Roblox, nice. Telegram, oh, hugging face, and hacker one. Oh, no, don't scroll further down. Interesting, the name here is Reuben Thompson. Let me view account here. Yep, deadcatx3 and Reuben Thompson. I do want to see the hugging face one, too. RT, maybe initials for Reuben Thompson. And look at this, masscan.cloud, what is that? Uh, oh, Flare says this domain, masscan.cloud, was used as the C2 or command and control during the Minishat worm infection in May. Look here, they have a, uh, write-up and I think they cover it down below. Oh, look, look, look, there is the, uh, Telegram percy_pcp alias and, uh, the other channel here. Where was the masscan.cloud? Oh, man, here's the react scanner, some of their docker configs, XMRig, the crypto miner. Where is the C2? Cube control, come on. Oh, I'm scrolling for a while, guys. Okay, this is when they were in their, uh, Telegram channel. Holy cow. Oh, there's a GitHub. Yeah, deadcat is, uh, pretty apt naming right now, huh? Look at it, it's right there in, uh, GitHub, too. And, okay, masscan.cloud, right in there. Geez. Okay, so, Reuben Thompson, it can't be that easy though, right? We got to dig in a bit more, find some more concrete evidence, right? But now we have a name, a potential name. So, let's bring that right back in to OSINT Industries. And what could we track down for that? All right, that scan is thinking Australia. Um, Reuben Thompson, I'm curious if we can get another emails, but, oh, uh, usernames, surfinup8b4f0. Okay. Well, I'm not seeing a ton of, uh, emails or things to like kind of pivot off of. What if we honed in on Australia? Like, is it dumb to just simply search for Reuben Thompson, Australia? Um, is there a LinkedIn page? Oh, doesn't exist. Look, take that for what you will, all right? Now, I'm speed running just a little bit because I know the investigation did lead to that Surfin Up 8 username, and it turns out it's tied to a Gmail address. Just super simple, surfinup8@gmail.com. Now, a wildly interesting thing you can do is kind of take a lot of the same threats that threat actors throw at us and kind of wonder, "Ooh, is there any insight on them?" And what I mean by that is taking a look at info-stealer malware logs. Were any of the hackers ever hacked themselves? In all of the data breaches and leaks across the history of the internet, could we track down that Gmail address and maybe find even passwords to pivot off of? So, what we'll do is use the Flare credential browser. Ooh, they have a nice new interface. Let me take a second to dig in the platform, and this is really cool. Oh, sorry, don't show my passwords or people with my name that have been caught in a breach. And this is really cool because we're actually being able to utilize this for a real cyber crime investigation. This is the awesome power of Flare. Let me search for surfinup8@gmail.com and passwords. This could help us prove some definitive use of online accounts, but now we're wondering, "Okay, what other accounts are tied to this email?" Now, the Flare research team could take some of these leaked passwords and take some of these email addresses and keep hunting. And they found a TikTok account that's associated with the username Yolo Solo 17. Now, I happen to be on this TikTok account's page, and it has only one video of what looks like a Steam account, Yolo CrownZ, and a lot of uh trading things here with uh scammer? I don't know. But, this is weird, right? I mean, I I guess there's a ban. You can see there's one VAC ban account on record. Is this Steam account somehow affiliated with Team PCP? The profile picture is a cat, but I don't know if it counts. So, this is a weird finding, right? And I don't know how much more there is to go off of of a TikTok video of a Steam account, but if we're getting scrappy and creative, I mean, could we be looking for other Steam friends or folks they play games with? You could use the context of Australia and some of the other information that's bubbled up in the investigation and Flare did it. And I want to pull up the picture here cuz it's kind of wild. Train Simulator Classic, a little bit of VRChat in Perth, Australia. And down below, we have Ellis. I can't really quite make out that profile picture, but if you look up their Steam account, they have a VAC ban on the exact same day that this TikTok account, Yolo Solo 17, Reuben Thompson, posts this video of a Steam account, March 7th, 2017. Here is the Steam account. Little bit of a higher quality picture for the profile picture you for you to see. A lot of time in VRChat, but here is the VAC list or VAC list entry. One VAC ban on record, September 13th, 2016. Now, that's not March 7th, 2017, but look closely here. What is that? 175 days since that ban? Timeline kind of lines up. And this profile picture is actually kind of unique. We could hone in on that. Even if we did a super simple little Google reverse image search, there's nothing really else there other than that stuff. Okay, I we don't need to record this part. So, at this point, we have an interesting new breadcrumb and puzzle piece. That profile picture, right? It feels unique, but we couldn't find anywhere else to run with it based off of just a Google image reverse search, but we've been building this mind map of the investigation and we know all these different aliases and identities that team PCP uses. So, what if we went back to the drawing board and kept taking a look at some of those other Telegram handles? So, no tricks up my sleeve here. What I want to do is hop over to the events tab on Flare and search for I'm going to unselect everything and just focus in on chats or Telegram chats and I want to search for just the username, right? pcp.sh Can we find any occurrences of chatter communication with that account across the history of their Telegram? And we have a couple hits from Maya the Fox and they say, "Just run this little EXE and boom." What is that EXE? I don't think I have to tell you. It is the same Steam profile picture. That is some pretty high confidence. That's the guy. That's the cat. Team PCP ringleader, literally the Telegram account that they've been chitchatting chirping with Cybercrime on is the exact same as the Steam profile picture tied to the accounts, all bringing us back to the name Reuben Thompson. I know we ran a little all over the map. I know this is a bit of an abbreviated showcase just to explain the whole investigation in the snapshot of a YouTube video. Obviously, there were so many more hey rabbit holes and things to dig into, but do you see the line? This all chains together and I think it's no longer circumstantial evidence to like high confidence. Hacker One account has their real name Reuben Thompson. That deadcatx3 handle is how you track down the Hacker One account and the Hugging Face domain, which has their C2 domain from the mini Shai Halud attack. That, of course, proves their Cybercrime shenanigans. They're bragging about it, chest thumping over on Telegram, but the same real name leads to a TikTok account where he has personally and voluntarily uploaded a video of a Steam account that got banned on the day that all has these puzzle pieces fall into place to find the exact same profile picture pointing definitely. I'm thinking that's the Team PCP leader. Reuben Thompson based out of Perth, Australia operating behind the identity deadcat x3. That single alias led to a verifiable person's identity and that was confirmed by law enforcement's arrest. Holy smokes everybody. I don't know if you had the same reaction that I do, but I just think that's a wild ride. Team PCP that made headlines for the entire year and that story unraveled. That identity unraveled. And the whole thing Team PCP was all about, you know, the hee hee ha ha's, the cats and the jokes, calling cards and logs, oh PCP was here. That cybercriminal wanted an audience and they got one. The Team PCP hacks and exploits and escapades were some of the most consequential supply chain incidents throughout the whole year. But that same person who wanted all this attention and spotlight for the memes, for the lols, and the kitty cat profile picture. Turns out there was another unique kitty cat profile picture that they left on a Steam profile for a decade just waiting for someone to find it and law enforcement confirmed the investigation and their identity and it led to their arrest. Damn everybody. Look, you know, Flare is a channel partner and I think they are just super cool. They have incredible threat intelligence. They do just so many cool things and it's just so it makes me feel so good to have the partners in the industry that do real work, that move the needle, that actually make such a cool difference in the security industry and raise up the whole security posture of everyone to take down hackers and cyber criminals. Man, it's just so cool. I I stayed up really late to try to get this video out the door because I know this was an under embargo story, but huge congrats, guys. What a win for the industry thanks to you. Please do give Flare some love with the link below in the video description. You know the drill, like, comment, subscribe. What an awesome story to tell.