TeamPCP Supply Chain Campaign: Update 002 - Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th)
2026-03-28T13:23:44Z•46186e4ff03a56f4575b159c2792c02947e5d1b46c488ebe1c302a70b05d0153
CISA KEVCheckmarxLiteLLMPyPITeamPCPTelnyxVect ransomwaredetection toolsmass-affiliate programransomwaresecurity-scannersupply-chainsupply-chain compromise
What happened
Update 002 (covering 2026-03-26 to 2026-03-27) for the TeamPCP supply-chain campaign: new findings include a Telnyx PyPI compromise (malicious packages uploaded), evidence Vect ransomware is operating a mass-affiliate program with a first publicly named victim claim, and expanded scope of affected tooling (Checkmarx) beyond initial reports. CISA added an entry to its KEV and detection tools and guidance are available. This continues a broader campaign that began Feb 28 (including the earlier LiteLLM PyPI compromise) in which a security scanner/tooling supply-chain was abused to distribute code
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 46186e4ff03a56f4575b159c2792c02947e5d1b46c488ebe1c302a70b05d0153
- Enrichment time
- 2026-03-28T13:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.