A week in security (March 30 – April 5)
2026-04-06T08:52:02Z•0c28a8dafd8cce2731b73b4e894728d62812d7aad9d41f5ff5817f21768b6675
ClickFixDarkSwordGlassWormInfiniti StealerNukeChainRATVenom StealerWhatsAppaxiosbrowser-extensioncredential-theftfraudiOSiPadOSjob-scammacOSnpmpatchremote-access-trojansoftware-updatesupply-chainvSIMvirtual-phonesvpn-auditwindows
What happened
Malwarebytes Labs (Mar 23–Apr 5, 2026) roundup covering multiple active threats and security developments: job-offer credential scams targeting Google/Facebook; an ongoing WhatsApp-for-Windows campaign that can gain persistent access; an npm supply-chain compromise of axios delivering a Remote Access Trojan; macOS threats including Infiniti (NukeChain) stealer using ClickFix and a fake-av site delivering Venom Stealer; GlassWorm browser-extension surveillance; and Apple quietly expanding DarkSword exploit mitigations to iOS/iPadOS 18.7.7. Coverage also highlights risks from rented virtual/soft
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 0c28a8dafd8cce2731b73b4e894728d62812d7aad9d41f5ff5817f21768b6675
- Enrichment time
- 2026-04-06T08:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.