As cited
Copy frozen at (site build).
threat intel
Crooks push Mac malware through fake OpenAI Codex ads
Attackers are using fake OpenAI Codex download pages to distribute Mac malware through sponsored Google search results. Victims are directed to a convincing Google Sites page where they are instructed to paste and execute a command in Terminal, which initiates a multi-stage infection chain. The malware shares characteristics with Atomic macOS Stealer (AMOS) and employs anti-analysis techniques to evade macOS security warnings.
Why it matters: Mac developers searching for artificial intelligence (AI) coding tools face immediate risk of malware infection; security teams should alert users to verify tool sources and avoid pasting unfamiliar commands, and monitor for similar campaigns targeting other artificial intelligence (AI) assistants like Claude.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Crooks push Mac malware through fake OpenAI Codex ads
Attackers are using fake OpenAI Codex download pages to distribute Mac malware through sponsored Google search results. Victims are directed to a convincing Google Sites page where they are instructed to paste and execute a command in Terminal, which initiates a multi-stage infection chain. The malware shares characteristics with Atomic macOS Stealer (AMOS) and employs anti-analysis techniques to evade macOS security warnings.
Why it matters: Mac developers searching for artificial intelligence (AI) coding tools face immediate risk of malware infection; security teams should alert users to verify tool sources and avoid pasting unfamiliar commands, and monitor for similar campaigns targeting other artificial intelligence (AI) assistants like Claude.
- Source published
- First seen by Cybersecurity Tracker