<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/scams-now-account-for-nearly-half-of-all-malware-detections-gen-digital-report-finds-p5bqdbecp" -->

---
title: Scams now account for nearly half of all malware...
description: Gen Digital&#x27;s H1 2026 Threat Report reveals scams now account for nearly 46% of all malware detections, marking a fundamental shift in cybercrime tactics. Key...
canonical: https://daily.dev/posts/scams-now-account-for-nearly-half-of-all-malware-detections-gen-digital-report-finds-p5bqdbecp
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Scams now account for nearly half of all malware detections, Gen Digital report finds | daily.dev
og:description: Gen Digital&#x27;s H1 2026 Threat Report reveals scams now account for nearly 46% of all malware detections, marking a fundamental shift in cybercrime tactics. Key...
og:url: https://daily.dev/posts/scams-now-account-for-nearly-half-of-all-malware-detections-gen-digital-report-finds-p5bqdbecp
og:image: https://api.daily.dev/og/posts/P5BQdbECp.png
og:image:alt: Scams now account for nearly half of all malware detections, Gen Digital report finds
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Scams now account for nearly half of all malware detections, Gen Digital report finds

**[Collections](https://daily.dev/sources/collections)** · 3 min read · 1 upvotes · 0 comments

## Summary

Gen Digital's H1 2026 Threat Report reveals scams now account for nearly 46% of all malware detections, marking a fundamental shift in cybercrime tactics. Key figures include 114.2 million fake e-shop attacks blocked, a 387% rise in government impersonation scams, and a 628% surge in breach notification alerts. The report also highlights supply chain attacks on npm and PyPI packages — including a compromised Cline CLI update — a new infostealer called Remus linked to the Lumma Stealer family, and a Rust-based clipboard hijacker targeting 21 blockchain types. AI agents are flagged as an emerging risk due to prompt injection and autonomous operation, prompting Gen to develop a runtime enforcement tool (Sage) and propose a cross-industry agent security standard (AARTS). The overarching theme: attackers are exploiting trust rather than bypassing defenses.

## Content

## The npm attack on Alibaba developers

For over three months, a cluster of 18 malicious npm packages quietly targeted developers at Alibaba Group before anyone caught it. Socket discovered the campaign by examining dependency trees rather than individual packages - which is exactly why it stayed hidden so long. No single package looked suspicious. The malice was distributed across the dependency chain so that each piece appeared benign in isolation.

The setup was methodical. Attackers found public code references to Alibaba's private, scoped npm packages, then registered unscoped packages with the same names - a dependency confusion attack aimed at developers with access to Alibaba's internal tooling. The 15 core packages were staged across different npm maintainer accounts, but the coordinated publishing on April 27-28 gave away the operation's structure.

Once installed, the packages used a Node.js vm sandbox escape to bypass security boundaries, then downloaded and executed a full remote access trojan. The RAT's capabilities are broad: command execution, arbitrary file upload and download, host reconnaissance, encrypted reverse TCP proxy, and lateral movement through DingTalk enterprise tools. C2 traffic was disguised with fake DingTalk headers to blend into normal enterprise network activity.

Persistence worked differently depending on the platform. On macOS, the malware modified `.zshrc` and installed a Launch Agent. On Windows, it replaced core code inside the Alilang security application - the security tool itself became the persistence mechanism. On Linux, it dropped a binary in `/tmp`.

Code comments written in Chinese and the targeting of Alibaba's internal tooling point toward industrial espionage. Affected teams should treat any compromised environment as fully breached and rotate all credentials from a clean machine.

---

## The broader picture: scams now drive nearly half of all detections

The Alibaba attack fits a pattern that Gen Digital's H1 2026 Threat Report documents across the wider threat landscape: attackers are increasingly exploiting trust rather than deploying obvious malware.

Scams now account for nearly 46% of all malware detections, making them the single largest threat category. The numbers behind specific scam types are striking:

- Tech support scams up 61.6%
- Government impersonation attacks up 387%
- Fake e-shop attacks: 114.2 million blocked
- Breach notification alerts up 628%

The supply chain vector isn't limited to npm either. A compromised update to the Cline CLI pushed malware directly to developer machines through a trusted workflow. PyPI has seen similar incidents.

On the malware side, a new infostealer called Remus has emerged, linked to the Lumma Stealer family. There's also a Rust-based clipboard hijacker targeting 21 different blockchain address formats - it sits quietly until you copy a crypto address, then swaps it for one the attacker controls.

Gen also flagged AI agents as an emerging execution risk. The concern isn't hypothetical: agents that operate autonomously with granted permissions create a new attack surface where malicious instructions can be injected into workflows without any obvious red flag. Gen's response includes a runtime enforcement tool called Sage and a proposed cross-industry standard called AARTS for agent security.

The thread connecting all of this - the npm cluster, the government impersonation scams, the compromised CLI update - is that none of it relies on breaking through defenses. It exploits legitimate infrastructure, real credentials, and permissions that were already granted. That's what makes it hard to catch, and why dependency tree analysis found what package scanning missed.

---

Tags: [#security](https://daily.dev/tags/security), [#ai-agents](https://daily.dev/tags/ai-agents), [#malware](https://daily.dev/tags/malware), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/scams-now-account-for-nearly-half-of-all-malware-detections-gen-digital-report-finds-p5bqdbecp)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Scams now account for nearly half of all malware detections, Gen Digital report finds","url":"https://daily.dev/posts/scams-now-account-for-nearly-half-of-all-malware-detections-gen-digital-report-finds-p5bqdbecp","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/scams-now-account-for-nearly-half-of-all-malware-detections-gen-digital-report-finds-p5bqdbecp"},"datePublished":"2026-07-27T12:08:34.441Z","dateModified":"2026-07-29T02:36:09.525Z","description":"Gen Digital's H1 2026 Threat Report reveals scams now account for nearly 46% of all malware detections, marking a fundamental shift in cybercrime tactics. Key...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d683d4fbe1e9b9313533cb23e77ad435?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d683d4fbe1e9b9313533cb23e77ad435?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/scams-now-account-for-nearly-half-of-all-malware-detections-gen-digital-report-finds-p5bqdbecp","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ai-agents,malware,phishing","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Scams now account for nearly half of all malware detections, Gen Digital report finds"}]}
```

