That dream job offer from Coca-Cola or Ferrari? It’s a trap for your passwords

2026-04-04T08:51:52Z573a784a58e711dcfa781373dbf389c8d9c392cce5d490b3461df4cbfd222b06
account-takeoveraxiosbrowser-extensionclickfixcredential-harvestdark sworddarkswordfraud-bypassglassworminfostealeriosjob-scammacosnpmpatchingphishingratremote-access-trojanrouter-security","vpn-audit","ai-misuse"social-engineeringsupply-chainvenom-stealervirtual-phoneswhatsappwindows

What happened

Collection of Malwarebytes posts (Mar–Apr 2026) describing multiple active and emerging threats: targeted job-offer phishing campaigns impersonating Coca‑Cola and Ferrari to harvest Google/Facebook credentials; ongoing WhatsApp-on-Windows campaign seeking persistent access; npm supply‑chain compromise of axios that dropped a RAT; macOS threats including Infiniti Stealer (ClickFix + Python/Nuitka) and fake Avast scans that install Venom Stealer; GlassWorm browser‑extension surveillance; FBI/CISA warnings about large-scale social‑engineering hijacks of Signal/WhatsApp; criminals renting virtual/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
573a784a58e711dcfa781373dbf389c8d9c392cce5d490b3461df4cbfd222b06
Enrichment time
2026-04-04T08:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.