GitHub Hacker EXPOSED BY HIS CAT

GitHub Hacker EXPOSED BY HIS CAT

Source: YouTube · John Hammond · published Aug 27, 2026 · 17:41

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF
Flare’s Emerging Threats Team successfully deanonymized the leader of Team PCP, a notorious hacker group that poisoned five major software ecosystems in early 2026, by tracing a single alias to a real identity 1:02. The investigation revealed that Reuben Thompson, based in Perth, Australia, was the operator behind the group's various online personas 8:54.

Key Takeaways:
• Team PCP executed a devastating supply chain attack in March 2026, using a single stolen GitHub token to compromise tools like Aqua Security’s Trivy, which resulted in backdoored code spreading to approximately 95 million monthly downloads 1:14.
• The group’s brazen behavior, including taunting victims and posting about their exploits on Telegram and X, created a digital footprint that investigators leveraged to link disparate accounts 2:50.
• The deanonymization process began with the alias "DeadCatX3," which led investigators to a HackerOne profile listing the name Reuben Thompson and a Hugging Face account containing command-and-control infrastructure 7:02.
• Investigators connected Thompson to a TikTok account that featured a Steam profile picture; cross-referencing this image with Telegram chats confirmed it matched the avatar used in cybercrime communications 11:06.
• Law enforcement confirmed the identity of the ringleader, leading to an arrest that brought an end to the group's reign over the software supply chain 15:36.

The case illustrates how threat actors' desire for recognition can inadvertently lead to their downfall, as their "bragging" provided the very breadcrumbs needed for their identification.

Sources:

  • 1:02 Introduction of Flare's deanonymization investigation into Team PCP.
  • 1:14 Details of the March 2026 supply chain attack affecting five ecosystems.
  • 2:50 Explanation of the group's boastful online behavior that aided the investigation.
  • 7:02 Tracing the "DeadCatX3" alias to a real name and C2 infrastructure.
  • 11:06 Linking the alias to a TikTok account and Steam profile picture.
  • 15:36 Confirmation of the leader's identity and subsequent arrest.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Last night I got an unexpected message. Someone I work with had said, "Hey John, just wanted to give you a heads-up that we have something cooking over here that I'm going to try and send you under embargo later today. Our biggest story yet." And I thought, "Ooh, that sounds ominous. Can I get a hint?" And they responded, "Something about cats." Um, cats? Later they messaged me again, "Hey John, here it is. We have deanonymized Team PCP." And I was just doom-scrolling on my couch just like, "What?" So I'm responding, "Holy That's a huge intel drop." And the last thing they say to me is "Thanks. If you want to cover it, you can recreate the whole investigation." So that's what we're doing today, everybody. We are going to OSINT investigate the leader of one of the most notorious hacker grou…