Traffic violation scams swap links for QR codes to steal your card details

2026-04-08T08:51:57Z34897ecbfb7d09edfca28cefe78dcd70710b52675ea7dd06c5ca13805b9845cc
axiosbrowser-extensionclickfixcredential-theftdarksworddata-breachglasswormhims-hersinfostealerios-patch','vpn-auditjob-scammacosnpmpersistencephishingpython-nuitkaqr-code-phishingratremote-access-trojansocial-engineeringsupply-chain-attacksupport-platform-breachtraffic-scamsvenom-stealerwhatsapp-windows

What happened

Malwarebytes Labs roundup covering multiple active threats and security developments: QR-code-based traffic/toll phishing and job-offer scams that steal credentials; a support-platform breach exposing Hims & Hers customer data; supply-chain compromise of the axios npm package dropping a RAT; fake Avast site distributing Venom Stealer; new macOS infostealer (Infiniti) abusing ClickFix and Python/Nuitka; GlassWorm browser-extension surveillance; and an ongoing WhatsApp-for-Windows campaign that establishes persistence. Also notes Apple expanding DarkSword mitigations to iOS/iPadOS 18.7.7, macOS'

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
34897ecbfb7d09edfca28cefe78dcd70710b52675ea7dd06c5ca13805b9845cc
Enrichment time
2026-04-08T08:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.