ON August 26, 2026, the Australian Federal Police arrested two core members of the cybercrime syndicate TeamPCP, which has been involved in significant open-source supply chain attacks, specifically targeting the Node Package Manager (NPM) ecosystem using malware known as 'Sandworm.' The arrested individuals, Ruben Ian Thomson and Louis Michael Gaebler, face a total of 14 severe criminal charges, including unauthorized data modification and handling criminal proceeds.
Despite their arrest, the decentralized nature of TeamPCP suggests that such cyber threats may continue, as the group previously released the source code for their malware publicly, leading to ongoing vulnerabilities in the software supply chain.