
Phished npm Maintainer Led to Debug/Chalk Hijack
Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…
Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures recipients to click “Complete Sync Account,” sending them through lookalike sites and a fake Google sign-in pop-up that captures credentials. The attack relies on brand trust (Google logos) and urgency (threats of service interruption) to drive clicks.
Cofense documented a phishing campaign that impersonates Google Ads MMC Sync accounts using a fake system upgrade or maintenance notice. The email pressures recipients to click a Complete Sync Account button, warning that failing to act within a set time frame will cause service interruptions or account limitations. Clicking the button starts a multi-step redirect: first to a Blogspot page displaying Google branding and a loading indicator, then to a newly registered lookalike domain, mcc-sync-ads[.]com. That final page presents a Google sign-in button that opens a JavaScript form built to imitate the real Google login and harvest whatever credentials are entered.
The campaign leans on two familiar social engineering levers: brand trust and urgency. The email prominently uses Google branding to appear legitimate, even though the sending domain, enavalenceart[.]com, has no connection to Google Ads. The urgent framing around account sync and threatened service disruption is designed to push recipients past normal scrutiny and toward the call to action before they check the sender address or the destination URLs.
Defenders can reduce the impact of this style of attack with a few habits:
This campaign is a reminder that credential theft attempts increasingly combine convincing brand impersonation with layered infrastructure, making sender verification and URL checks essential habits for teams managing advertising or other SaaS platform accounts.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
An email impersonating Google Ads MMC Sync warned recipients to manually sync their account or face service interruptions. Clicking the Complete Sync Account button led through a Blogspot page to a lookalike domain with a fake Google sign-in form that captured credentials.
The sending email domain was enavalenceart[.]com rather than a Google domain, and the final phishing page used a newly registered lookalike domain, mcc-sync-ads[.]com, neither of which is owned by Google.
Check the actual sender email domain rather than trusting the display name or logo, be wary of urgent account sync or upgrade demands, and avoid signing in through embedded pop-ups that appear mid-redirect.
Marketing, digital advertising, and growth teams that manage Google Ads MMC accounts are primary targets, though the brand impersonation could affect any general workforce recipient.
You get an email: "Complete Sync Account" or your Google Ads MMC might be limited. Looks official, Google logos and all. You click the button. First a Blogspot page flashes with a Google Ads logo and loading bar, then you land on mcc-sync-ads.com with a big Google sign-in button. Here’s the trick: that Google sign-in pop-up is just a JavaScript form on mcc-sync-ads.com, not a real Google page. Your email and password go straight to them. One move: if a Google Ads sync email feels urgent, don’t click it. Go to ads.google.com or your normal bookmark and check your account from there.

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…