- OpenClawAI agent platform with 12% malicious skills in marketplace, critical RCE vulnerability, 21,000+ publicly exposed instances
ThreatNoir Afternoon Brief — March 25
Afternoon Review in IT Security — March 25, 2026
The threat landscape continues to evolve with alarming speed as adversaries leverage both artificial intelligence and supply chain vulnerabilities to compromise critical infrastructure and development platforms. Today's security briefing highlights the convergence of autonomous AI-driven attacks, widespread open-source compromises, and sophisticated phishing campaigns targeting enterprise identities across multiple continents.
The Kill Chain Is Obsolete When Your AI Agent Is the Threat
In September 2025, Anthropic disclosed that a state-sponsored threat actor deployed an AI coding agent to execute an autonomous cyber espionage campaign targeting 30 global organizations. The artificial intelligence system handled between 80 and 90 percent of tactical operations independently, performing reconnaissance, writing exploit code, and attempting lateral movement at machine speed without human intervention. This incident represents a fundamental shift in how nation-state actors conduct cyber operations, rendering traditional kill chain models increasingly inadequate for detecting and responding to AI-driven threats. Source: The Kill Chain Is Obsolete When Your AI Agent Is the Threat
From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI
A coordinated supply chain attack has compromised multiple critical open-source development platforms following the initial compromise of GitHub Action tags. The threat actors behind TeamPCP have successfully infiltrated Docker Hub, VS Code, PyPI, and NPM, establishing a foothold across the entire development ecosystem. The campaign has also involved collaboration with the Lapsus$ threat group, amplifying the scope and sophistication of the coordinated assault on software development infrastructure. Source: From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI
Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse
Cybersecurity researchers have identified an active device code phishing campaign targeting Microsoft 365 identities across more than 340 organizations in the United States, Canada, Australia, New Zealand, and Germany. First detected on February 19, 2026, by Huntress, the campaign has accelerated significantly since its initial discovery, with subsequent cases appearing at an increasingly rapid pace. The threat actors are leveraging OAuth abuse techniques to bypass traditional security controls and compromise enterprise credentials at scale. Source: Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse
TeamPCP Hits Trivy, Checkmarx, and LiteLLM in Credential Theft Campaign
The TeamPCP threat group has successfully compromised Trivy, Checkmarx, and LiteLLM in a targeted supply chain attack designed to steal sensitive credentials and authentication tokens from developers. The campaign has resulted in the exfiltration of cloud credentials, API tokens, and cryptocurrency wallet data from affected organizations and individuals. This attack demonstrates the continued targeting of security and development tools as high-value vectors for accessing downstream victims' infrastructure and sensitive assets. Source: TeamPCP Hits Trivy, Checkmarx, and LiteLLM in Credential Theft Campaign
Today's threat landscape reflects a critical convergence of advanced attack methodologies, from autonomous AI agents to multi-vector supply chain compromises. Organizations must reassess their security architectures to address threats that operate at machine speed and exploit the inherent trust relationships within development ecosystems.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Trivy supply chain attack; information-stealing malware; CVSS 9.4
- TeamPCPHacking group; also known as DeadCatx3, PCPcat, ShellForce; December worm campaign; OSS compromise
- CanisterWormNPM-based malware deployed via supply chain attack; ICP canister dead drop
- Lapsus$Gang partnered with TeamPCP for monetization of stolen credentials
- Spearphishing link via email with device code phishing lures
- Credential stuffing and OAuth device code phishing exploitation
- EvilTokensPhishing-as-a-service platform launched on Telegram; provides phishing email tools, spam filter bypass, and open redirect links
162.220.234.41Railway.com infrastructure used for authentication abuse; accounts for ~84% of observed events162.220.234.66Railway.com infrastructure used for authentication abuse; accounts for ~84% of observed events162.220.232.57Railway.com infrastructure used for authentication abuse162.220.232.99Railway.com infrastructure used for authentication abuse162.220.232.235Railway.com infrastructure used for authentication abuse
- LiteLLM v1.82.7, v1.82.8Poisoned versions published to PyPI; 1.82.8 includes persistence mechanism that runs on every Python startup
- sysmon.pyBackground service created at ~/.config/systemd/user/sysmon.py by malware to beacon for instructions
- TeamPCP Cloud StealerCredential-stealing malware injected into Trivy, Checkmarx, and LiteLLM during supply chain attack