A week in security (March 30 – April 5)

2026-04-06T08:52:02Z0c28a8dafd8cce2731b73b4e894728d62812d7aad9d41f5ff5817f21768b6675
ClickFixDarkSwordGlassWormInfiniti StealerNukeChainRATVenom StealerWhatsAppaxiosbrowser-extensioncredential-theftfraudiOSiPadOSjob-scammacOSnpmpatchremote-access-trojansoftware-updatesupply-chainvSIMvirtual-phonesvpn-auditwindows

What happened

Malwarebytes Labs (Mar 23–Apr 5, 2026) roundup covering multiple active threats and security developments: job-offer credential scams targeting Google/Facebook; an ongoing WhatsApp-for-Windows campaign that can gain persistent access; an npm supply-chain compromise of axios delivering a Remote Access Trojan; macOS threats including Infiniti (NukeChain) stealer using ClickFix and a fake-av site delivering Venom Stealer; GlassWorm browser-extension surveillance; and Apple quietly expanding DarkSword exploit mitigations to iOS/iPadOS 18.7.7. Coverage also highlights risks from rented virtual/soft

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
0c28a8dafd8cce2731b73b4e894728d62812d7aad9d41f5ff5817f21768b6675
Enrichment time
2026-04-06T08:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.