Yes, that email is really from Paypal. And, yes, it's really malicious.
Score another one for the bad guys, who have yet again demonstrated their seemingly inexhaustible ability to concoct new methods to exploit legitimate services in order to bypass existing ...
