logo

Supply Chain Attacks Surge in March 2026

ID: fcb82cbb-c40b-5181-8a64-ab6f4a8da9ee

STIX ID: report--fcb82cbb-c40b-5181-8a64-ab6f4a8da9ee

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: ThreatLabz (Zscaler)

...
...

This Zscaler ThreatLabz blog documents a surge of software supply-chain attacks in March 2026, highlighting an Axios NPM package compromise that injected a postinstall dependency delivering a cross-platform Remote Access Trojan (RAT) contacting C2 at sfrclak.com, and a TeamPCP-led compromise of LiteLLM on PyPI that used a .pth autorun and obfuscated payloads to harvest cloud/API/SSH/Kubernetes credentials; the report lists affected versions, file and network IOCs, and detailed remediation and hardening recommendations for package management, CI/CD, secrets handling, and incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.