logo

Fake OpenAI Codex Installer Tricks Mac Users Into Pasting Malware Into Terminal

ID: b64394b2-fd71-5b51-834e-e4e26f09e739

STIX ID: report--b64394b2-fd71-5b51-834e-e4e26f09e739

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Varshini

...
...

The report details a malicious campaign where attackers place sponsored Google ads and host convincing Google Sites pages that impersonate an OpenAI Codex download portal. macOS victims are socially engineered (ClickFix) to paste a Terminal command that decodes a remote URL, downloads a staged shell loader and then a universal Mach-O payload staged to /tmp/helper; the chain uses obfuscation (Base64 and AES-encrypted gzip), telemetry tagged with event=pasted, and removes extended attributes to reduce macOS warnings; researchers note strong overlap with Atomic macOS Stealer (AMOS) and provide several IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.