TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)
2026-04-27T19:23:50Z•c4c38c95595afb22f19b58b22e588c051fb2b1ec6e02726204439ae201cd1c1a
BitwardenCVE-2026-28950CVE-2026-33634CanisterSprawlCheckmarx KICSCiscoPyPISANDCLOCKTeamPCPTrivyUNC6780campaigncredential-theftmalwarenpmsoftware-supply-chainsupply-chainsupply-chain-wormxinference
What happened
SANS ISC Update: The TeamPCP supply‑chain campaign (operators designated UNC6780, credential stealer “SANDCLOCK”) resumed after a 26‑day pause with multiple concurrent compromises during Apr 20–26, 2026. Confirmed impacts include compromises of Checkmarx KICS, a Bitwarden CLI cascade, a malicious xinference PyPI package, and identification of a CanisterSprawl npm worm; the campaign has also been linked to Trivy‑linked credential theft (used to steal Cisco source code) and continued credential‑monetization activity. The feed also notes the lapsed CISA KEV remediation deadline for CVE-2026-33634
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- c4c38c95595afb22f19b58b22e588c051fb2b1ec6e02726204439ae201cd1c1a
- Enrichment time
- 2026-04-27T19:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.