
Phished npm Maintainer Led to Debug/Chalk Hijack
Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…
Recorded Future reports the Golden Chickens (TAG-195) malware-as-a-service operation has resurfaced with four new malware families, including TinyEgg and ChonkyChicken. The group (and a linked operator TAG-127) has used ClickFix-style social engineering that tricks people into manually running malicious commands, leading to malware installation and credential theft from web browsers.
Recorded Future reports that the Golden Chickens malware-as-a-service operation, tracked as TAG-195, has resurfaced with four new malware families: TinyEgg, ChonkyChicken, a modular ChonkyChicken variant, and ChromEggscalator. A linked operator, TAG-127, has been observed delivering TinyEgg through ClickFix-style social engineering, a technique that tricks users into manually executing malicious commands rather than relying on a traditional malicious attachment or link.
The lure typically appears as a generic help page or fix guide that tells the user to copy and run a command in a terminal or Run prompt to resolve an issue. When the victim complies, the attack chain downloads an OCX payload from attacker-controlled staging infrastructure, resulting in the installation of TinyEgg on the system.
ClickFix lures work because they shift the malicious action onto the user rather than automating it through a script or exploit. Because the victim is the one typing and executing the command, many technical controls that would otherwise flag automated payload delivery are bypassed. The pretext also avoids naming a specific brand, making it broadly applicable across many types of fake fix pages, which increases its reach across Windows and macOS users alike.
Once TinyEgg is installed, follow-on payloads escalate the impact quickly. ChonkyChicken is described as a fully featured implant that expands on TinyEgg with browser credential theft and can even control a live browser session using the Chrome DevTools Protocol. A modular version of ChonkyChicken can load up to 14 capability modules on demand, including keylogging, screen capture, clipboard capture, network reconnaissance, and persistence management. ChromEggscalator is noted as a successor to a prior credential-stealing tool. This shows how quickly access gained through a single copy-pasted command can turn into full credential and session compromise.
This attack pattern maps to techniques such as user execution of malicious instructions (T1204.001) and gathering victim information to shape the lure (T1598).
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Golden Chickens, tracked as TAG-195, is a malware-as-a-service operation that Recorded Future reports has resurfaced with four new malware families, including TinyEgg and ChonkyChicken.
ClickFix-style lures present a fake fix page or instructions that tell a user to copy and run a command in a terminal or Run prompt, which downloads a payload and installs malware such as TinyEgg.
ChonkyChicken expands on TinyEgg with browser credential theft and can even control a live browser session using the Chrome DevTools Protocol, and a modular variant can load 14 additional capability modules like keylogging and screen capture.
Watch for any page or pop-up asking you to copy and paste a command to fix an issue, unusual file downloads like OCX components, and instructions that skip verification through official IT channels.
If a web page ever says, "Fix required: copy and run this command", stop. That’s the ClickFix trap. Groups like Golden Chickens, TAG-195, use this to push malware like TinyEgg and ChonkyChicken. You copy the command, it quietly downloads an OCX file from their server and installs TinyEgg. From there, ChonkyChicken can grab your saved browser passwords and even ride your live Chrome sessions using DevTools, plus modules for keylogging and screen capture. Aha rule: if any web page tells you to copy‑paste a command to fix something, don’t run it, send a screenshot to IT and ask first.

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Researchers observed insurance-themed phishing that doesn’t just steal passwords, it hijacks accounts in real time while the victim is actively logging in. The…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…