Traffic violation scams swap links for QR codes to steal your card details

2026-04-07T20:52:07Z4de85a03510ba1307e5e65b892e8f10fa9bc933691b858aa6e5904a309d6d3f5
SIM-virtualizationaxiosbrowser-extensionclickfixcredential-theftdarksworddata-breachglassworminfiniti-stealerinfostealeriosjob-offer-scam','vpn-audit','ai-agentmacosnpmpayment-fraudphishingpython-nuitkaqr-code-phishingremote-access-trojansupply-chain-attacksupport-platform-breachvenom-stealervirtual-phones-fraudwhatsapp-campaignwindows

What happened

Malwarebytes Labs (late Mar–early Apr 2026) reports multiple active threats and incidents across platforms: QR-code-based traffic/toll phishing that steals card details; a support-platform breach exposing Hims & Hers customer data; an npm supply‑chain compromise of axios that dropped a Remote Access Trojan; fake Avast sites installing Venom Stealer; a new macOS infostealer (“Infiniti Stealer”) abusing ClickFix and Python/Nuitka; the GlassWorm campaign that installs fake browser extensions for surveillance; Microsoft warnings about campaigns targeting WhatsApp on Windows; Apple expanding DarkS­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
4de85a03510ba1307e5e65b892e8f10fa9bc933691b858aa6e5904a309d6d3f5
Enrichment time
2026-04-07T20:52:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Traffic violation scams swap links for QR codes to steal your card details · Baitaphish