TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)

2026-04-27T19:23:50Zc4c38c95595afb22f19b58b22e588c051fb2b1ec6e02726204439ae201cd1c1a
BitwardenCVE-2026-28950CVE-2026-33634CanisterSprawlCheckmarx KICSCiscoPyPISANDCLOCKTeamPCPTrivyUNC6780campaigncredential-theftmalwarenpmsoftware-supply-chainsupply-chainsupply-chain-wormxinference

What happened

SANS ISC Update: The TeamPCP supply‑chain campaign (operators designated UNC6780, credential stealer “SANDCLOCK”) resumed after a 26‑day pause with multiple concurrent compromises during Apr 20–26, 2026. Confirmed impacts include compromises of Checkmarx KICS, a Bitwarden CLI cascade, a malicious xinference PyPI package, and identification of a CanisterSprawl npm worm; the campaign has also been linked to Trivy‑linked credential theft (used to steal Cisco source code) and continued credential‑monetization activity. The feed also notes the lapsed CISA KEV remediation deadline for CVE-2026-33634

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
c4c38c95595afb22f19b58b22e588c051fb2b1ec6e02726204439ae201cd1c1a
Enrichment time
2026-04-27T19:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.