{
  "id": 3231991,
  "title": "Crooks push Mac malware through fake OpenAI Codex ads",
  "url": "https://urgent.news/2026/08/25/crooks-push-mac-malware-through-fake-openai-codex-ads",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-25T09:15:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/08/25/crooks-push-mac-malware-through-fake-openai-codex-ads/5291899"
  },
  "original_language": "en",
  "account": "Hackers are employing fraudulent OpenAI Codex download pages to deceive Mac developers into executing malicious code disguised as installation commands. Cato Networks researchers discovered the scheme after noticing sponsored Google search results targeting individuals seeking to download Codex for macOS. The deceptive ads lead potential users to a well-crafted download page on Google Sites, complete with the familiar OpenAI branding. However, no Codex is present; instead, the fraudulent site instructs Mac users to open Terminal, input a supplied command, and execute it. While presented as part of the installation process, the command surreptitiously initiates a multi-stage malware infection. This is a variation of the prevalent ClickFix technique, where attackers entice victims to execute harmful commands themselves rather than relying on a deceptive attachment or executable.\n\nIn this instance, the command begins with what appears to be a legitimate npm instruction for installing Codex. However, it is followed by code that decodes a Base64-encoded URL, retrieves an attacker-controlled shell script, and pipes it into zsh. This script downloads another stage, which contacts the attacker's server to confirm that someone has fallen for the ruse before downloading a Mach-O executable to \"/tmp/helper.\" It then clears macOS's security information, making the malware less likely to trigger warnings before it launches. Cato reported that the final binaries are universal Mach-O files, capable of running natively on both Intel-powered Macs and newer Apple Silicon machines.\n\nThe researchers identified significant similarities between this campaign and Atomic macOS Stealer, also known as AMOS, an infostealer previously distributed via fake software downloads and malicious advertising campaigns. While Cato has not officially labeled the malware as AMOS, numerous indicators suggest a strong connection, from the attack's staging to the construction of the final payload. The criminals have also taken measures to prevent researchers from closely examining their creation. Although victims are initially directed to Google Sites, the malicious content is embedded within the page via an iframe, pulling data from attacker-controlled infrastructure based on factors such as the visitor's operating system and the path taken to reach the site. This infrastructure adjusts the displayed content to appear harmless when the visitor is deemed unsuitable for the attackers' purposes.\n\nCato observed that the decoy site offered download buttons for both macOS and Linux, but only the Mac variant was found to deliver the malware chain. Codex is not the only AI coding assistant being targeted in this manner. Cato discovered a similar ClickFix page masquerading as Anthropic's Claude Code, sharing infrastructure with the Codex campaign. Attackers don't need to exert much effort to find their targets, as developers searching for Codex inadvertently help them by pushing the fake download page above legitimate results in Google sponsored ads.",
  "summary": "Sponsored search results lead developers straight into a ClickFix malware trap",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 5,
    "also_reported_by": [
      {
        "outlet": "9to5Mac",
        "title": "OpenAI restores 5-hour Codex and Work limits for ChatGPT Plus users",
        "url": "https://urgent.news/2026/08/25/openai-restores-5-hour-codex-and-work-limits-for-chatgpt-plus-users",
        "published": "2026-08-25T01:47:49.000Z"
      },
      {
        "outlet": "The Indian Express",
        "title": "ChatGPT for Teens promises safer AI. Will its safeguards work for Indian users?",
        "url": "https://urgent.news/2026/08/25/chatgpt-for-teens-promises-safer-ai-will-its-safeguards-work-for",
        "published": "2026-08-25T04:17:25.000Z"
      },
      {
        "outlet": "TechRadar",
        "title": "ChatGPT Plus costs me $20 a month — using it to question my spending has already saved me more than that",
        "url": "https://urgent.news/2026/08/25/chatgpt-plus-costs-me-20-a-month-using-it-to-question-my-spending-has",
        "published": "2026-08-25T10:40:55.000Z"
      },
      {
        "outlet": "CNBC",
        "title": "OpenAI bans Russian ChatGPT accounts used in covert misinformation campaign",
        "url": "https://urgent.news/2026/08/25/openai-bans-russian-chatgpt-accounts-used-in-covert-misinformation",
        "published": "2026-08-25T11:21:09.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}