logo

TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)

ID: d55c1a13-793d-577f-8923-274c21db42be

STIX ID: report--d55c1a13-793d-577f-8923-274c21db42be

Feed Name: SANS ISC Diary

Threat Score
88/100

Date Published: 2026-03-28

Date Updated: 2026-04-19

...
...

**Executive Summary:** This update reports that TeamPCP — an active supply-chain campaign that has repeatedly compromised package registries (PyPI, npm) and stolen large credential troves — paused new package compromises over a 48-hour window while shifting toward monetization via a Vect ransomware affiliate program; the report also describes sophisticated exfiltration techniques (GitHub Releases), a Farsi-aware Kubernetes wiper, substantial credential fan-out, published defensive detections from vendors, and prioritized recommendations for credential rotations, IOC sweeps, and CI/CD behavioral monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.