TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)
2026-03-29T19:23:48Z•ff23663d7ff20a6230b61d816ced697d4bbc9e5f98f1e7f17ef6239ad9331b95
Apple-patchesArechClient2CISA-KEVCheckmarxIP-KVMLiteLLMNetSupportPyPIRemcosSectopStealCTeamPCPTelnyxVectdetection-toolsmalwareransomwaresupply-chainsupply-chain-compromisethreat-intel
What happened
SANS ISC updates (Mar 24–28, 2026) track the TeamPCP supply‑chain campaign as it shifts into a monetization phase: PyPI compromises (LiteLLM earlier and a reported Telnyx package compromise), a Vect ransomware partnership and first named victim claims. Checkmarx scope appears broader than initially reported, CISA added related entries to the KEV, and detection tools and guidance have been published; the campaign reported no new compromises in the past 48 hours. Related SANS posts highlight an unrelated SmartApeSG malware campaign (Remcos, NetSupport, StealC, Sectop/ArechClient2), Apple’s March
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- ff23663d7ff20a6230b61d816ced697d4bbc9e5f98f1e7f17ef6239ad9331b95
- Enrichment time
- 2026-03-29T19:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.