Threats & Adversaries · Supply Chain

TeamPCP Pauses New Supply-Chain Compromises, Monetizes Haul

TeamPCP paused new package compromises for 48 hours. The group shifted focus to monetizing stolen credentials through a Vect ransomware affiliate. Analysts warn the group's ~300 GB credential trove enables future supply-chain intrusions and CISA added CVE‑2026‑33634 to the KEV.

2 sources · Apr 1

CVE-2026-33634

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 9

Timeline

Sources

Part of the PlainSec briefing for 2026-03-28

Every edition of this story: TeamPCP Pauses New Supply-Chain Compromises, Monetizes Haul

More from today