Supply Chain Attacks Surge in March 2026
ID: fcb82cbb-c40b-5181-8a64-ab6f4a8da9ee
STIX ID: report--fcb82cbb-c40b-5181-8a64-ab6f4a8da9ee
Feed Name: Security Boulevard
This Zscaler ThreatLabz blog documents a surge of software supply-chain attacks in March 2026, highlighting an Axios NPM package compromise that injected a postinstall dependency delivering a cross-platform Remote Access Trojan (RAT) contacting C2 at sfrclak.com, and a TeamPCP-led compromise of LiteLLM on PyPI that used a .pth autorun and obfuscated payloads to harvest cloud/API/SSH/Kubernetes credentials; the report lists affected versions, file and network IOCs, and detailed remediation and hardening recommendations for package management, CI/CD, secrets handling, and incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
