TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, (Wed, Apr 1st)

2026-04-01T13:23:47Z04cc413e726e016bd1975328bad1580f3f9bb56e04286abcc21adc3080b6dcdb
astrazenecacloud-enumerationconfirmed-victimdata-exfiltrationdata-leakdatabrickspost-compromise-enumerationpypi-compromiseransomwaresecurity-scannersupply-chainsupply-chain-campaignsupply-chain-compromiseteampcptelnyxthreat-intelligencevect-ransomware

What happened

SANS ISC reports continued developments in the TeamPCP supply-chain campaign (update through 2026-04-01): operators abused a security scanner supply chain to distribute malicious code, confirmed at least one victim disclosure, and documented post-compromise cloud enumeration and data exfiltration. Recent activity includes a Telnyx PyPI compromise, partnership with/leveraging of Vect ransomware (dual ransomware operations), public data releases (AstraZeneca reported), a Databricks investigation, and narrowing attribution reported by Axios. This remains an active, high-impact supply-chain and r×

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
04cc413e726e016bd1975328bad1580f3f9bb56e04286abcc21adc3080b6dcdb
Enrichment time
2026-04-01T13:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.