TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, (Mon, Mar 30th)
2026-03-31T01:23:47Z•79ba9bb519222209429db25aacc2b5a76add4dff234b5f26ee282b5d77c05424
Apple March 2026 patchesAstraZenecaCISA KEVCheckmarxDatabricksLiteLLMNetSupport RATPyPI compromiseRemcos RATSectop (ArechClient2)SmartApeSGStealCTeamPCPTelnyxVect ransomwaredetection-toolsdual-operationshoneypot analysismonetization-phaseransomwaresupply-chainsupply-chain-campaign
What happened
SANS ISC diary entries (Mar 25–30, 2026) provide multiple updates on the TeamPCP supply-chain campaign (“When the Security Scanner Became the Weapon”, v3.0). Key findings: TeamPCP continues supply-chain compromises originating Feb 28, 2026, with recent PyPI compromises (LiteLLM, Telnyx) and an operational shift into monetization (Vect ransomware affiliate partnership and dual ransomware operations). TeamPCP allegedly released AstraZeneca data and Databricks is reported to be investigating an alleged compromise. Checkmarx scope appears broader than initially reported; CISA added related entries
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 79ba9bb519222209429db25aacc2b5a76add4dff234b5f26ee282b5d77c05424
- Enrichment time
- 2026-03-31T01:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.