- EmilGroupSupply chain attack affecting 28 packages (March 20th)
- TeamPCPProlific threat actor conducting coordinated supply chain attacks
- TrivyCompromised package (March 19th)
ThreatNoir Weekend Brief — March 28
Morning Review in IT Security — March 28, 2026
The threat landscape continues to intensify as March draws to a close, with supply chain attacks dominating the security agenda alongside critical vulnerabilities affecting major platforms. Nation-state actors are escalating their operations while criminal enterprises expand their infrastructure for monetizing breaches.
TeamPCP Escalates Supply Chain Attack Campaign
TeamPCP has launched an unprecedented wave of supply chain attacks, with over fifty compromised packages discovered within an eight-day period. The threat actor targeted critical open-source projects including Trivy on March 19th and EmilGroup with 28 malicious packages on March 20th. Source: vxunderground
This campaign represents a significant escalation in the frequency and scale of supply chain operations, raising concerns about the security posture of widely-used development tools and libraries.
Apple Issues Lock Screen Alerts for Web-Based Exploits
Apple has begun sending Lock Screen notifications to users running outdated versions of iOS and iPadOS, warning them of active web-based attacks targeting unpatched devices. The alerts urge users to install critical updates to protect their devices from exploitation. Source: The Hacker News
This proactive notification approach represents Apple's response to documented attacks against out-of-date iOS software, signaling the severity of vulnerabilities present in older versions of the operating system.
TeamPCP Compromises Telnyx Package on PyPI
TeamPCP has successfully compromised the Telnyx Python package by publishing two malicious versions, 4.87.1 and 4.87.2, to the Python Package Index on March 27, 2026. The malicious versions concealed credential harvesting capabilities within WAV files, enabling data theft from unsuspecting developers who installed the package. Source: The Hacker News
The use of steganographic techniques to hide malicious payloads within audio files demonstrates the increasing sophistication of supply chain attack methodologies.
Fake VS Code Alerts Spread Malware on GitHub
A widespread campaign is targeting developers on GitHub by posting fraudulent Visual Studio Code security alerts in project Discussion sections, deceiving users into downloading malware. The campaign exploits developers' trust in legitimate security notifications to distribute malicious code. Source: Bleeping Computer
This attack vector highlights the vulnerability of developer communities to social engineering tactics that leverage the appearance of official security communications.
SnowTeam Launches Leak Bazaar Criminal Platform
SnowTeam has introduced Leak Bazaar, a corporate data exchange platform equipped with machine learning-powered dump analysis, database management system reverse engineering capabilities, and ransomware negotiation support services. Source: Dark Web Informer
The platform represents a significant evolution in criminal infrastructure, providing threat actors with sophisticated tools to monetize stolen data and facilitate ransomware operations.
Iranian Threat Actor Compromises FBI Director's Personal Email
Handala, a suspected Iranian-based threat actor group, has successfully compromised the personal email account of Kash Patel, the current Director of the Federal Bureau of Investigation. The compromised emails span from 2010 to 2022. Source: vxunderground
This high-profile compromise represents a significant intelligence victory for the nation-state actor and underscores the persistent threat posed by advanced persistent threat groups targeting U.S. government officials.
Google Accelerates Quantum-Safe Cryptography Transition
Google has established a 2029 deadline for transitioning to post-quantum cryptographic standards as researchers warn that quantum computers could break current encryption protocols sooner than previously anticipated. Source: Hack Read
The accelerated timeline reflects growing concerns within the cybersecurity community about the imminent threat quantum computing poses to existing cryptographic infrastructure.
The convergence of supply chain vulnerabilities, nation-state operations, and emerging quantum computing threats underscores the critical need for organizations to reassess their security postures and implement comprehensive defense strategies across development pipelines, endpoint security, and cryptographic infrastructure.
TeamPCP has done ANOTHER supply chain attack.
My Brother in Christ, how many of these fuckin' th... Source: [TeamPCP has done ANOTHER supply chain attack.
My Brother in Christ, how many of these fuckin' th...](https://x.com/vxunderground/status/2037588996235088320)
TeamPCP has done ANOTHER supply chain attack.
My Brother in Christ, how many of these fuckin' things are you going to do? YOU'VE DONE 50 FUCKING SUPPLY CHAIN ATTACKS. 50 SUPPLY CHAIN ATTACKS IN EIGHT FUCKING DAYS.
March 19th:
- Trivy
March 20th:
- EmilGroup (28 packages)
- https://t.co/MjrPcXZnOt
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- DarkSwordiOS exploit kit targeting iOS 18.4–18.7
- CorunaiOS exploit kit targeting iOS 13.0–17.2.1; evolution of Operation Triangulation framework
- Operation TriangulationSophisticated zero-click iMessage campaign targeting iPhones; original framework for Coruna
- TeamPCPThreat actor conducting supply chain attacks across multiple ecosystems
- msbuild.exeWindows persistence mechanism dropped in Startup folder by telnyx malware
83.142.209.203C2 and exfiltration server receiving stolen credentials on port 8080
drnatashachinn.comCommand-and-control domain hosting JavaScript reconnaissance payload and traffic distribution system
- BlackSnowAlias/operator of SnowTeam behind Leak Bazaar launch
- SnowTeamThreat actor group operating Leak Bazaar platform
- Leak BazaarDark web data exchange platform operated by SnowTeam/BlackSnow for monetizing stolen corporate data
- HandalaIranian-based threat actor group responsible for compromising FBI Director's email