Weekly review

ThreatNoir Morning Brief — March 27

2026-03-27Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — March 27, 2026

The cybersecurity landscape continues to face multifaceted threats spanning supply chain attacks, critical AI vulnerabilities, state-sponsored espionage, and sensitive military data exposure. Today's briefing covers four significant security incidents that demand immediate attention from defenders and organizations across sectors.

New Ghost Campaign Uses Fake npm Progress Bars to Phish Sudo Passwords

ReversingLabs researchers have identified a sophisticated campaign dubbed Ghost that leverages deceptive npm install logs and progress bars to manipulate developers into surrendering their sudo passwords and cryptocurrency wallet credentials. The attackers employ social engineering tactics disguised within legitimate-looking package manager interfaces to lower victim defenses. Source: Hackread

The campaign has been observed distributing malicious packages including react-state-optimizer-core, coinbase-desktop-sdk, and @openclaw-ai/openclawai through npm repositories. The threat actors utilize the domain teletype.in as part of their infrastructure. This attack demonstrates how supply chain threats continue to evolve by targeting developer credentials rather than solely compromising application functionality, creating a dual risk of immediate system access and financial asset theft.

CISA: New Langflow Flaw Actively Exploited to Hijack AI Workflows

The Cybersecurity and Infrastructure Security Agency has issued a warning regarding active exploitation of a critical vulnerability in the Langflow framework, identified as CVE-2026-33017, which enables attackers to hijack AI agent workflows. Source: Bleeping Computer

The vulnerability affects systems used for building and deploying artificial intelligence agents, representing a concerning intersection of AI security and critical infrastructure risk. Exploitation has been observed in the wild within hours of public disclosure, indicating rapid adversary adoption. Organizations deploying Langflow should prioritize patching efforts immediately, as the framework's role in AI orchestration means compromised instances could enable broad lateral movement and data exfiltration.

China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks

A persistent campaign attributed to the China-nexus threat actor Red Menshen, also tracked as Earth Bluecrow, has successfully embedded kernel-level implants within telecom network infrastructure to conduct espionage against government targets. Source: The Hacker News

The threat actor deploys the BPFDoor malware alongside secondary tools including CrossC2, Sliver, and TinyShell to maintain persistent access while evading detection. The strategic positioning within critical telecommunications networks provides adversaries with exceptional vantage points for monitoring government communications and conducting further lateral movement. This campaign exemplifies the sophisticated capabilities of state-sponsored actors in maintaining long-term presence within sensitive infrastructure.

U.S. Air Force Air Mobility Command Operations Data Exposed on Cybercrime Forum

A post appearing on a prominent cybercrime forum claims to contain U.S. Air Force Air Mobility Command operations logs related to Operation Lions Roar and Epic Fury 2026, including detailed flight information showing over 716 flights to Middle East locations with 16 currently in progress. Source: Dark Web Informer

The exposure of operational military data on public cybercrime forums represents a significant breach of operational security and could enable adversaries to track force movements, identify vulnerable transport corridors, and coordinate targeting efforts. The specificity of the disclosed information, including current flight operations, suggests either a substantial compromise of military information systems or a credible insider threat scenario requiring immediate investigation.

Today's threat landscape underscores the necessity for comprehensive security strategies addressing supply chain integrity, rapid vulnerability patching, advanced persistent threat detection, and operational security enforcement across all organizational levels.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

New Ghost Campaign Uses Fake npm Progress Bars to Phish Sudo Passwords
Malware6
  • @openclaw-ai/openclawai
    Similar malicious package discovered March 8, 2026, suggesting larger attack wave
  • coinbase-desktop-sdk
    Malicious npm package targeting cryptocurrency wallet theft
  • Ghost campaign
    Supply-chain attack campaign using fake npm install logs to phish sudo passwords
  • Remote Access Trojan (RAT)
    Deployed after obtaining sudo credentials to steal crypto wallets and personal data
  • react-state-optimizer-core
    Malicious npm package using fake install logs as phishing vector
  • [email protected]
    Malicious npm package with separate decryptor file for stolen data
Domain1
  • teletype.in
    Used by [email protected] variant for command and control communication
China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks
MITRE ATT&CK3
  • ICMP-based covert communication between compromised hosts
  • Kernel modules and extensions used for persistence via BPFDoor
  • Phishing and exploitation of edge services for initial access
Malware4
  • BPFDoor
    Linux kernel-level backdoor abusing Berkeley Packet Filter for covert C2 and persistence in telecom networks
  • CrossC2
    Linux-compatible beacon framework deployed post-exploitation by Red Menshen
  • Sliver
    Post-exploitation tool deployed by Red Menshen for lateral movement and credential harvesting
  • TinyShell
    Unix backdoor deployed by Red Menshen for persistent access