Threats & Adversaries · Supply Chain

TeamPCP Pauses New Supply-Chain Compromises, Monetizes Haul

TeamPCP maintained a multi‑target supply‑chain campaign dating to March 19. No new package compromises were confirmed in the past 48 hours. Analysts say operators have shifted to monetizing harvested credentials and announced a Vect ransomware affiliate.

2 sources · Apr 1

CVE-2026-33634

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 9

Timeline

Sources

Part of the PlainSec briefing for 2026-03-29

Every edition of this story: TeamPCP Pauses New Supply-Chain Compromises, Monetizes Haul

More from today