Traffic violation scams swap links for QR codes to steal your card details
2026-04-08T08:51:57Z•34897ecbfb7d09edfca28cefe78dcd70710b52675ea7dd06c5ca13805b9845cc
axiosbrowser-extensionclickfixcredential-theftdarksworddata-breachglasswormhims-hersinfostealerios-patch','vpn-auditjob-scammacosnpmpersistencephishingpython-nuitkaqr-code-phishingratremote-access-trojansocial-engineeringsupply-chain-attacksupport-platform-breachtraffic-scamsvenom-stealerwhatsapp-windows
What happened
Malwarebytes Labs roundup covering multiple active threats and security developments: QR-code-based traffic/toll phishing and job-offer scams that steal credentials; a support-platform breach exposing Hims & Hers customer data; supply-chain compromise of the axios npm package dropping a RAT; fake Avast site distributing Venom Stealer; new macOS infostealer (Infiniti) abusing ClickFix and Python/Nuitka; GlassWorm browser-extension surveillance; and an ongoing WhatsApp-for-Windows campaign that establishes persistence. Also notes Apple expanding DarkSword mitigations to iOS/iPadOS 18.7.7, macOS'
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 34897ecbfb7d09edfca28cefe78dcd70710b52675ea7dd06c5ca13805b9845cc
- Enrichment time
- 2026-04-08T08:51:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.