TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)
2026-03-29T07:23:43Z•a814bb9e2e8cd2222bfe5c47ed8d536f57cc65042ec447e3743d22a3165fb89f
CISACheckmarxKEVLiteLLMPyPITelnyxVectdetectionincident-responsemonetizationransomwaresecurity-scannersoftware-supply-chainsupply-chainsupply-chain-compromiseteamPCP
What happened
SANS ISC updates on the TeamPCP supply-chain campaign (v3.0) covering developments through Mar 27–28, 2026: the campaign has shifted to a monetization/operational-tempo phase with Vect ransomware moving to a mass affiliate model and at least one named victim claimed. Recent supply-chain compromises include LiteLLM (earlier) and a Telnyx PyPI compromise; detection tools and mitigations have been published and CISA added an entry to its KEV list. Checkmarx’s exposure appears broader than initially reported. As of Mar 28 there were no new compromises observed in the prior 48 hours. Also noted: a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- a814bb9e2e8cd2222bfe5c47ed8d536f57cc65042ec447e3743d22a3165fb89f
- Enrichment time
- 2026-03-29T07:23:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.