TeamPCP Supply Chain Campaign: Update 002 - Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th)
2026-03-28T07:23:45Z•149dd7541626ebc2b955dda5778fbc94532f2877c3b3127b87139426d882dfe0
Apple-patchesCISA-KEVCheckmarxIP-KVMLiteLLMNetSupportPyPIRemcosSectopSmartApeSGStealCTeamPCPTelnyxVect-ransomwaredetection-toolsmalicious-packageransomware-affiliatesupply-chain
What happened
SANS ISC diary updates (Mar 24–27, 2026) highlight an evolving TeamPCP software supply‑chain campaign in which attackers abused security tooling and PyPI packages (including recent LiteLLM and a reported Telnyx PyPI compromise) to distribute malicious code and enable Vect ransomware activity via a mass affiliate program; a first named victim claim was published and Checkmarx scope appears broader than initially reported with a CISA KEV entry and published detection tools. Separate reporting describes the SmartApeSG campaign distributing multiple RATs (Remcos, NetSupport, StealC, Sectop/ArechCl
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 149dd7541626ebc2b955dda5778fbc94532f2877c3b3127b87139426d882dfe0
- Enrichment time
- 2026-03-28T07:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.