TeamPCP Supply Chain Campaign: Update 002 - Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th)

2026-03-28T13:23:44Z46186e4ff03a56f4575b159c2792c02947e5d1b46c488ebe1c302a70b05d0153
CISA KEVCheckmarxLiteLLMPyPITeamPCPTelnyxVect ransomwaredetection toolsmass-affiliate programransomwaresecurity-scannersupply-chainsupply-chain compromise

What happened

Update 002 (covering 2026-03-26 to 2026-03-27) for the TeamPCP supply-chain campaign: new findings include a Telnyx PyPI compromise (malicious packages uploaded), evidence Vect ransomware is operating a mass-affiliate program with a first publicly named victim claim, and expanded scope of affected tooling (Checkmarx) beyond initial reports. CISA added an entry to its KEV and detection tools and guidance are available. This continues a broader campaign that began Feb 28 (including the earlier LiteLLM PyPI compromise) in which a security scanner/tooling supply-chain was abused to distribute code

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
46186e4ff03a56f4575b159c2792c02947e5d1b46c488ebe1c302a70b05d0153
Enrichment time
2026-03-28T13:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · TeamPCP Supply Chain Campaign: Update 002 - Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th) · Baitaphish