TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, (Mon, Mar 30th)

2026-03-31T01:23:47Z79ba9bb519222209429db25aacc2b5a76add4dff234b5f26ee282b5d77c05424
Apple March 2026 patchesAstraZenecaCISA KEVCheckmarxDatabricksLiteLLMNetSupport RATPyPI compromiseRemcos RATSectop (ArechClient2)SmartApeSGStealCTeamPCPTelnyxVect ransomwaredetection-toolsdual-operationshoneypot analysismonetization-phaseransomwaresupply-chainsupply-chain-campaign

What happened

SANS ISC diary entries (Mar 25–30, 2026) provide multiple updates on the TeamPCP supply-chain campaign (“When the Security Scanner Became the Weapon”, v3.0). Key findings: TeamPCP continues supply-chain compromises originating Feb 28, 2026, with recent PyPI compromises (LiteLLM, Telnyx) and an operational shift into monetization (Vect ransomware affiliate partnership and dual ransomware operations). TeamPCP allegedly released AstraZeneca data and Databricks is reported to be investigating an alleged compromise. Checkmarx scope appears broader than initially reported; CISA added related entries

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
79ba9bb519222209429db25aacc2b5a76add4dff234b5f26ee282b5d77c05424
Enrichment time
2026-03-31T01:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.