Video summary

GitHub Hacker EXPOSED BY HIS CAT

Main summary

Key takeaways

News and Commentary

Summary of the video’s main points

  • Breaking lead and premise: The creator describes receiving an embargoed tip from a coworker about a major cybersecurity disclosure tied to “Team PCP.” The plan is to recreate the investigative process used to identify (deanonymize) the operator behind the hacker group.

What Team PCP is accused of doing

  • The group is described as evolving from opportunistic cloud exploitation (late 2025) into software supply-chain attacks (early 2026).
  • Early activity involved:
    • scanning for exposed services/APIs,
    • infecting hosts,
    • propagating via compromised infrastructure (botnet-like behavior).
  • The later shift targets trusted software dependencies used in CI/CD environments and common developer tooling.

Key supply-chain incident described (the “stolen token” case)

  • A single stolen token is said to have enabled an attacker to poison multiple software ecosystems over ~5 days.
  • The attack is characterized as beginning with a misconfigured GitHub workflow in Aqua Security’s Trivy (a widely deployed vulnerability scanner).
  • The attackers allegedly obtained access by stealing a service account token:
    • Aqua rotated credentials but was said to have missed some, leaving a foothold.
  • The attackers later allegedly published a malicious Trivy release across distribution channels, causing CI/CD credential-stealing backdoors.
  • “Domino” impact is explained as downstream builds executing the poisoned component:
    • other software builds (e.g., light LLM) allegedly ran the component,
    • which then enabled harvesting of publishing tokens and resulted in backdoored releases.
  • The video claims light LLM gets about ~95 million downloads/month, emphasizing scale and impact.

OSINT / deanonymization workflow (how the identity was allegedly uncovered)

  • The investigation focuses on aliases used by the group, especially one recurring handle: “DeadCatX3.”
  • The presenter claims “OSINT Industries” (and Flare tools) were used to map relationships among:
    • usernames,
    • accounts,
    • infrastructure.
  • The investigation purportedly linked DeadCatX3 to a real person name: “Reuben Thompson.”
  • Additional corroboration is described through other platforms (e.g., HackerOne, Hugging Face, Telegram aliases), including references to infrastructure/domain material said to be tied to prior malware activity (including a cited C2 domain used in a worm incident).

Credential-breach log pivot attempt (claimed but framed as investigatory)

  • The video describes using Flare’s credential browser to query a leaked email tied to the suspected identity (surfinup8@gmail.com).
  • It claims the leaked context led to more accounts (including a TikTok username “Yolo Solo 17”) that contained additional breadcrumbs.

Steam / profile-picture “puzzle piece” used for linking

  • A major claim is that a unique cat profile picture on:

    • suspected operator accounts (Telegram/other aliases), and
    • a Steam account/video uploaded by “Reuben Thompson” share the same visual identity.
  • The presenter discusses timeline-style “match” reasoning around bans and upload dates, using the cat profile picture as a high-confidence linking artifact.

  • The video asserts that linkage across Steam / TikTok / Telegram / HackerOne / Hugging Face converges on Reuben Thompson, associated with Perth, Australia, operating under the DeadCatX3 identity.

Outcome: arrest and verification

  • The presenter states that a law enforcement arrest confirmed the identity and that the deanonymization was no longer circumstantial.
  • The video frames this as the culmination of a hacker who sought attention for “cat” branding and memes, but who left reusable identifiers that ultimately enabled identification.

Presenters / contributors (as mentioned)

  • Flare (including its Emerging Threats Team, and Flare’s platform/tools)
  • Brian Krebs (mentioned as having also investigated the topic)
  • John (the presenter speaking on the video)
  • Aqua Security (organization whose Trivy workflow/token handling is discussed)
  • Forbes (mentioned due to a Team PCP interview)

Original video