The QR Code Hiding in Plain Text: This Week's Sneakiest Phishing Trick
Attackers built scannable QR codes out of typed characters to slip past image-blocking filters, while a trusted developer tool shipped credential-stealing code.

Key points
- Attackers this week built working QR codes out of plain text characters, so the codes still render even when a mail client blocks images.
- Blocking images in email, a common precaution against tracking pixels and malicious graphics, does not stop this trick.
- A trusted developer software source pushed out code that quietly stole login credentials, hitting people who thought they were installing something safe.
- A network management protocol meant to keep systems secure was itself abused in fresh attacks.
- The fixes are old-fashioned: check the sender, do not scan random codes, and use multi-factor authentication wherever it is offered.
Here is the annoying thing about this week's phishing round-up: one of the tricks defeats a precaution many careful people actually use.
A lot of us tell friends and family to turn off automatic image loading in email. It is a sensible habit. It stops tracking pixels, tiny hidden images that tell a sender you opened their message. It also stops booby-trapped graphics.
This week, attackers found a way around it.
How does a QR code work without an image?
The criminals built the QR code out of typed characters. Rows of block-shaped symbols, arranged so that when your phone camera looks at the screen, it reads them as a real QR code and opens a link.
No image file. Nothing for your mail app to block. The pattern is just text, the same as the words in this sentence, and text always renders.
Point a phone at it and you land on whatever site the attacker chose. Usually a fake login page dressed up as Microsoft 365, a bank, or a delivery company.
This is a twist on what the industry has been calling quishing, which is simply phishing that uses QR codes instead of clickable links. QR-based phishing already dodges a lot of email security, because scanners look at links in the message body, not at what a picture might contain. Making the code out of text pushes that gap a bit wider.
What should ordinary readers do about it?
Treat a QR code in an email the way you would treat a stranger handing you a note with a web address on it. Slow down. Ask why it is there.
If a message from your bank, employer or a delivery firm wants you to scan a code, open the app or type the address yourself. Do not use the code. Real companies almost never need you to scan something from an email to log in.
And where the site offers it, turn on multi-factor authentication, the second step that asks for a code from your phone or a tap on an app. If a phishing page steals your password, that second step is often what stops the criminals actually getting in.
The other stories worth knowing
A trusted source for developer software shipped a package that stole credentials from anyone who installed it. This is a supply chain attack: instead of hacking you directly, criminals poison something you already trust and wait for you to pull it in. The Hacker News flagged the incident in its weekly wrap.
A protocol used to manage network equipment, the plumbing that keeps offices and homes online, was also abused this week to hijack routers. If your internet provider or IT team asks you to reboot or update a router, do it promptly.
| Trick this week | What it targets | What actually helps |
|---|---|---|
| QR code made of text | People who block email images | Do not scan codes from email |
| Poisoned developer package | Software teams and their logins | Pin versions, use MFA on code accounts |
| Router protocol abuse | Home and office network gear | Apply firmware updates quickly |
None of this is exotic. It is the same old game: convince a human to click, scan or install. The details change every week. The defence, mostly, does not.



