isc.sans.edu 3/28/2026, 4:05:36 PM · via preferred

TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)

TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)
CyberSIXT Evidence Panel
Primary Source paloaltonetworks.com
CISA KEV Listed in KEV
Patch Patch Available

THE third update on the TeamPCP supply chain campaign notes that no new package compromises have been confirmed in the first 48-hour window since the Telnyx disclosure on 27 March 2026, marking a pause after an aggressive cadence that previously saw targets such as Trivy, CanisterWorm and others.

Analysts suggest the shift toward monetisation of existing credential harvests, rather than expanding the ecosystem, while emphasising this pause does not signal an end to operations; stolen credentials from an estimated 300 GB trove could still drive future compromises. PyPI has quarantined two TeamPCP campaigns in quick succession, which may raise attack costs for the operators.

The report also highlights new detection guidance and defensive measures, including behavioural detection for CI/CD pipeline attacks and a focus on anomalous runner activity, such as memory reads and unusual archive creation. The CISA KEV remediation deadline for CVE-2026-33634 is 8 April 2026, with a watch item noting ongoing potential expansion to other registries and continued investigation into AstraZeneca’s breach claim, which remains unconfirmed at 48 hours.

View Primary Source Via isc.sans.edu

Article by CyberSIXT