logo

Fake OpenAI Codex download tricks macOS users into installing malware

ID: 57fadf71-4108-5a18-886f-f07e75ce41c9

STIX ID: report--57fadf71-4108-5a18-886f-f07e75ce41c9

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Sinisa Markovic

...
...

Cato Networks identified an active macOS malware campaign that used sponsored search ads and Google Sites landing pages impersonating developer tools (OpenAI Codex and Claude Code) to trick users into pasting a Base64-decoded command into Terminal; the command pipes obfuscated zsh stages that fetch and execute a universal Mach-O payload. The attackers used iframe-hosted interchangeable content and device gating to evade analysis, and the delivery chain and artifacts strongly overlap with the Atomic macOS Stealer family.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.