VibeCoded

Two arrests in the TeamPCP open-source supply chain spree

September 1, 2026. From issue 4 of The Compliance Brief, one story for founders shipping AI-built and vibe coded apps.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Issue 4 of The Compliance Brief was published on September 1, 2026. One of its 5 stories bears on AI security, LLM attacks and app security flaws, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Krebs on Security

The Australian Federal Police arrested two men in Western Australia, aged 21 and 23, over alleged membership in TeamPCP. The group is blamed for what Krebs describes as the longest running spree of software supply chain attacks, built around malicious open-source packages that hit thousands of businesses globally.

Our take, in short

Arrests are good news and change nothing about your dependency tree, because the packages that were published are still out in caches and lockfiles. What I would do this week is confirm you can produce an SBOM for your production build on demand and that someone reviews new transitive dependencies before they ship.

Read the full take on traztech.ca

Also in issue 4

Outside AI security, LLM attacks and app security flaws, but in the same email:

Older: issue 2 All issues on VibeCoded Newer: issue 5