Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Crooks Leverage Fake OpenAI Codex Ads to Infect Macs with Malware




Crooks are using fake OpenAI Codex ads to trick Mac developers into running malware disguised as installation commands, a new threat that highlights the ongoing battle against sophisticated phishing attacks and the importance of cybersecurity awareness among developers. Researchers at Cato Networks have uncovered a campaign involving sponsored Google search results that direct users to a convincing-looking download page hosted on Google Sites. The malware, a variation of the increasingly popular "ClickFix" technique, convinces victims to execute malicious commands themselves rather than relying on a dodgy attachment or executable to do the dirty work.

  • Crooks are using fake OpenAI Codex ads to trick Mac developers into running malware disguised as installation commands.
  • Researchers at Cato Networks have uncovered a campaign involving sponsored Google search results that direct users to a convincing-looking download page hosted on Google Sites.
  • The fake site tells Mac users to open Terminal, paste in a supplied command, and run it, which kicks off a multi-stage malware infection.
  • The malware uses the "ClickFix" technique, convincing victims to execute malicious commands themselves rather than relying on a dodgy attachment or executable.
  • The attackers have taken steps to evade detection, including using iframe infrastructure and checking visitor details to show harmless-looking content.
  • The use of fake ads highlights the ongoing threat posed by sophisticated phishing attacks and the need for developers to be vigilant and take steps to protect themselves.



  • Crooks are using fake OpenAI Codex ads to trick Mac developers into running malware disguised as installation commands, a new threat that highlights the ongoing battle against sophisticated phishing attacks and the importance of cybersecurity awareness among developers. Researchers at Cato Networks have uncovered a campaign involving sponsored Google search results that direct users to a convincing-looking download page hosted on Google Sites, complete with the familiar OpenAI branding. However, instead of serving up an installer, the fake site tells Mac users to open Terminal, paste in a supplied command, and run it. The instructions are dressed up as part of the installation process, but the command quietly kicks off a multi-stage malware infection.

    The malware, which is a variation of the increasingly popular "ClickFix" technique, convinces victims to execute malicious commands themselves rather than relying on a dodgy attachment or executable to do the dirty work. The command begins with what appears to be a legitimate npm instruction for installing Codex, but tacked onto it is code that decodes a Base64-encoded URL, fetches an attacker-controlled shell script, and pipes it into zsh. The script then pulls down another stage, which contacts the attacker's server to report that someone has taken the bait before downloading a Mach-O executable to "/tmp/helper." It then removes security information macOS uses to flag suspicious downloads, helping the malware dodge the usual warnings before it launches.

    The researchers found substantial similarities between the campaign and Atomic macOS Stealer, better known as AMOS, an infostealer previously spread through fake software downloads and malicious advertising campaigns. While Cato isn't quite ready to slap an AMOS label on the malware, they say plenty of fingerprints point in that direction, from how the attack is staged to how the final payload is built. The crooks have also taken steps to keep researchers from getting a good look at their handiwork. Although victims initially land on Google Sites, the malicious content itself is pulled into the page from attacker-controlled infrastructure using an iframe. That infrastructure checks details including the visitor's operating system and the path used to reach it, allowing it to show harmless-looking content when a visitor doesn't fit the profile the attackers are after.

    The attackers don't have to work particularly hard to find their victims, either. Developers searching Google for Codex do that work for them, with sponsored ads pushing the fake download page above the legitimate results. This highlights the ongoing struggle between cybersecurity experts and attackers, who are continually evolving their tactics to evade detection and stay one step ahead of their adversaries. It also underscores the importance of cybersecurity awareness among developers, who are often the first line of defense against these types of attacks.

    In recent months, there have been several high-profile incidents of fake software downloads and malicious advertising campaigns being used to infect machines with malware. These incidents highlight the ongoing threat posed by sophisticated phishing attacks and the need for developers to be vigilant and take steps to protect themselves against these types of attacks. By staying informed and taking proactive measures to secure their systems, developers can help prevent these types of attacks from succeeding and protect their machines from infection.

    The use of fake OpenAI Codex ads to infect Macs with malware is just the latest example of the creativity and cunning of attackers. As the threat landscape continues to evolve, it's essential that developers and cybersecurity experts remain vigilant and work together to stay one step ahead of these threats. By doing so, we can help protect our machines and our data from falling prey to these types of attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Crooks-Leverage-Fake-OpenAI-Codex-Ads-to-Infect-Macs-with-Malware-ehn.shtml

  • https://www.theregister.com/security/2026/08/25/crooks-push-mac-malware-through-fake-openai-codex-ads/5291899


  • Published: Tue Aug 25 04:55:11 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us