The latest ThreatsDay roundup from The Hacker News packs a wide mix of stories into one briefing: malicious VS Code themes, npm supply-chain attacks, AI phishing, a ransomware affiliate betrayal, exposed hacker tools and a WhatsApp remote access trojan (RAT). Not every item touches ordinary users directly, but several share a common thread. The WhatsApp RAT and AI phishing threats in particular rely on persuading a person to trust something they should not, and that is where your habits matter most.
The source summary is brief, so this post sticks to what it names and focuses on practical context rather than speculation about details the roundup does not spell out.
What the WhatsApp RAT means for everyday users
A remote access trojan gives an attacker a degree of control over an infected device. Depending on the malware, that can include viewing files, capturing activity or running further commands. When such a tool is delivered through a messaging app, the risk is different from a typical email scam: messages arrive from a contact, a group or a number that looks plausible, and people tend to lower their guard in chat.
The roundup lists the WhatsApp RAT as one of its headline items, but the summary does not give technical specifics. What we can say is that the delivery channel is the part worth your attention. Messaging apps blend personal and work conversations, so a single careless tap on a file or link can affect both.
Sensible precautions apply whatever the exact mechanism:
- Treat unexpected attachments and links as suspect, even from known contacts, and confirm through another channel if something feels off.
- Avoid installing apps or files that arrive through chat, especially anything prompting you to enable extra permissions.
- Review which devices are linked to your account in the app's settings, and remove any you do not recognize.
- Turn on the app's two-step verification and keep the app and your operating system updated.
Malicious VS Code themes and npm attacks: the developer supply-chain risk
Two items in the roundup point at software developers: malicious Visual Studio Code themes and npm supply-chain attacks. Both exploit trust in the ecosystem. Editor extensions and open-source packages are convenient precisely because they are easy to install, and that same ease means a harmful one can reach many machines quickly.
If you do not write code, this may seem distant. It is not entirely. Developers hold credentials, access tokens and source code, and compromises there can ripple outward into the products and services everyone else uses. If you are a hobbyist or professional developer, extension hygiene is the practical response:
- Install only what you need, and prefer extensions and packages with a visible history and active maintenance.
- Check the publisher name carefully, since lookalike names are a common trick.
- Remove extensions and dependencies you no longer use.
- Keep secrets out of your editor environment where possible, and rotate tokens if you suspect exposure.
The same logic extends to browser extensions for non-developers: each one is software with access to your activity, so vet it like any other app.
How AI is making phishing harder to spot
The roundup also names AI phishing. The old advice to look for clumsy grammar and odd phrasing is losing value, because generated text can be fluent, tailored and fast to produce at scale. Our earlier coverage of an AI agent that hacked 30 companies for just $4 each illustrates how cheap and repeatable AI-assisted attacks can become, and the same economics favor phishing campaigns.
The takeaway is to shift from judging how a message reads to judging what it asks you to do. Requests for codes, urgent payments, logins through a link or a QR scan to "verify" an account deserve a pause no matter how polished the message looks. Go directly to the official app or website instead of following the link provided.
This is also why phishing-resistant multi-factor authentication matters. One-time codes can be handed to an attacker by a convincing impersonator. Passkeys and hardware security keys are bound to the real site, so they are much harder to trick you into giving away.
Practical steps to reduce your exposure
What This Means For You: most of these threats succeed through trust, not brute technical force. A few habits close off a large share of the risk.
- Harden your messaging apps. Enable two-step verification, review linked devices, and restrict who can add you to groups.
- Vet extensions and packages. Whether for your browser or code editor, install sparingly, check publishers and clear out unused add-ons.
- Move to phishing-resistant MFA. Prefer passkeys or hardware security keys over SMS or app codes for important accounts such as email, banking and cloud storage.
- Verify out of band. If a message asks for something sensitive, confirm using a separate, trusted channel.
- Keep software updated. Patches close the doors that malware tends to walk through.
A VPN does not stop any of the threats above by itself. It encrypts your connection, but it will not stop you from opening a malicious file or approving a fake login, so treat it as one layer among several.
Conclusion and next steps
The WhatsApp RAT and AI phishing threats in this ThreatsDay edition are a reminder that attackers go where people already feel comfortable: chat apps, trusted extensions and familiar-looking messages. Spend ten minutes this week reviewing your messaging app security settings, trimming the extensions you rarely use, and switching your most important accounts to passkeys or security keys.
For broader context on where risk is concentrating, see our earlier ThreatsDay roundup on self-rewriting AI agents and the ThreatsDay roundup covering Odysseus RCE and a Samsung flaw. Together they show a consistent pattern: the best defenses are usually the simple, consistent ones.




