
Phished npm Maintainer Led to Debug/Chalk Hijack
Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…
Researchers observed a long-running tech support scam that sent over 13 million emails, mostly to Japanese “.jp” addresses, pushing victims to fake security alert websites. The lures increasingly looked like workplace HR and internal IT notices, aiming to trick employees into clicking links, calling a bogus support line, and ultimately paying fees or moving money while attackers remotely controlled the device.
This campaign combined mass email distribution with fake security warning websites and phone-based social engineering. Over a 165 day period, researchers observed more than 13 million emails, with 94% sent to addresses using Japan's .jp top-level domain. The emails used spoofed senders designed to look like the recipient's own address or a legitimate internal service, moving victims from a deceptive email to a fraudulent support call.
Clicking the link in these emails opened a fake site displaying a bogus security warning. That page pushed the victim to call a listed support number. Once on the phone, the attackers posed as technical support staff and often requested remote control of the victim's device. From there, the scheme moved through three stages: lure the user to the fake alert page, gain remote control while impersonating support staff, and then extract money through fraudulent support fees or wire transfers.
The lures increasingly mimicked ordinary workplace communications rather than generic security pop-ups. Starting in May 2026, subject lines referenced internal network security audits, confidential performance evaluations and promotion lists, and employee benefit notices like digital gift cards for a company anniversary. This shift toward workplace themed lures reflects an attempt to reach individuals inside companies and organizations, likely aiming for larger payouts than typical consumer targeting.
The combination of spoofed senders, rapidly rotating fake alert sites, and legitimate hosting and remote access services made the scam harder to filter and more convincing once a victim reached the fake warning page.
Organizations can reduce exposure by tightening sender authentication and building specific habits among employees:
Because these lures now closely resemble routine workplace notices, awareness training should specifically cover HR and IT themed phishing, not just generic security alert scams.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers sent spoofed emails mimicking internal HR or IT notices with links to fake security alert sites, which pressured victims to call a bogus support line where scammers requested remote device access.
According to the research, 94% of the more than 13 million emails observed over 165 days were sent to addresses using Japan's .jp top-level domain.
In confirmed cases, victims were coached to access their online banking accounts while attackers remotely controlled their devices, resulting in substantial financial losses.
Enforcing SPF, DKIM, and DMARC helps detect spoofed senders, and employees should avoid calling numbers shown in unsolicited security warning pop-ups, verifying alerts through official channels instead.
You get an email: "[Confidential] H2 performance evaluations and promotion list." Tempting, right? This is part of a 13‑million‑email tech support scam hitting .jp addresses. Click the link, and instead of HR, you land on a fake security alert page screaming that your device is infected and you must call support now. If you call, the "support" person walks you through installing a remote access tool, then calmly guides you into your online banking. That HR email just turned into a live money-transfer session under their control. Aha test: if an "internal" HR or IT email sends you to a scary security page with a phone number, stop. Close it, and contact HR or IT using your usual company channels, not that page.

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics…

A Russian-linked group allegedly stole sensitive contact data from the Netherlands National Police after getting access to an employee’s email account. The…

Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures…