Fake OpenAI Codex and Claude Code ads push ClickFix malware to macOS developers

Attackers are buying Google search ads for fake OpenAI Codex and Anthropic Claude Code download pages to trick Mac developers into infecting themselves. The campaign uses the ClickFix technique: victims are told to paste a Terminal command that appears to install Codex with npm but actually decodes a hidden URL, downloads shell scripts, strips macOS quarantine protections, and launches a universal Mach-O payload. Cato Networks found similarities to Atomic macOS Stealer (AMOS), though attribution is not confirmed.
Why it matters: Developers looking for AI coding tools are being targeted through normal web searches, so the risk is immediate for Mac users who install tools from ads or copy Terminal commands from web pages. Users should avoid sponsored download links, verify domains before installing developer tools, and treat any install flow that asks for pasted shell commands as high risk.

Sources

Crooks push Mac malware through fake OpenAI Codex ads
2026.08.25 100% relevant
This article establishes a distinct malvertising and ClickFix malware campaign centered on fake Codex and Claude Code download pages targeting macOS developers.
← Back to all stories