Australia charged 2 men with 14 offenses.

The malware still infects any pipeline that trusts a signed, expected update.

The worm hijacked CI/CD pipelines, so a single poisoned build shipped malicious code as trusted software to every downstream user.

Authorities call TeamPCP a “prolific group” but have charged only 2 of its members.

Sources: Ars Technica