TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)
2026-03-28T19:23:47Z•3a5543cfe9cab7b5cb1b7c4447a0075d0503b172606d73aa577fee7a386cf872
Apple-patchesCISA-KEVCheckmarxIP-KVMLiteLLMNetSupportPyPISmartApeSGTeamPCPTelnyxVectransomwareremcossupply-chainsupply-chain-monetization
What happened
SANS ISC diary batch (Mar 24–28, 2026) focused on the TeamPCP supply‑chain campaign (report: “When the Security Scanner Became the Weapon”, v3.0) and related developments. Key updates (Updates 001–003) document the campaign from initial access (Feb 28) through multiple PyPI compromises (LiteLLM and Telnyx), Checkmarx involvement appearing broader than originally reported, CISA KEV entry for affected packages, and the campaign’s shift into a monetization phase via a Vect ransomware mass‑affiliate partnership and a first named victim claim. As of Update 003 (Mar 28) operators reported no new (s)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 3a5543cfe9cab7b5cb1b7c4447a0075d0503b172606d73aa577fee7a386cf872
- Enrichment time
- 2026-03-28T19:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.