TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)
2026-03-29T01:23:47Z•364108f24562d7fcf283b86a819f3fc3725b71893e448f8af1a7032a1a22ea71
checkmarxcisa-kevdetectionliteLLMmalwaremonetizationpypiransomwaresoftware-supply-chainsupply-chainsupply-chain-compromiseteampcptelnyxthreat-actorvect
What happened
SANS ISC updates on the TeamPCP supply‑chain campaign (report v3.0, Mar 25, 2026) detail a shift into a monetization phase. Confirmed activity includes PyPI compromises (LiteLLM earlier and a reported Telnyx PyPI compromise), a partnership with Vect ransomware and its mass‑affiliate program, and the first named victim claim. Recent updates note Checkmarx scope may be larger than originally reported, a CISA KEV entry and available detection tools; operational tempo has shifted but no new compromises were observed in the 48 hours through Mar 28, 2026.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 364108f24562d7fcf283b86a819f3fc3725b71893e448f8af1a7032a1a22ea71
- Enrichment time
- 2026-03-29T01:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.