Fake OpenAI Codex download tricks macOS users into installing malware
ID: 57fadf71-4108-5a18-886f-f07e75ce41c9
STIX ID: report--57fadf71-4108-5a18-886f-f07e75ce41c9
Feed Name: Help Net Security
Cato Networks identified an active macOS malware campaign that used sponsored search ads and Google Sites landing pages impersonating developer tools (OpenAI Codex and Claude Code) to trick users into pasting a Base64-decoded command into Terminal; the command pipes obfuscated zsh stages that fetch and execute a universal Mach-O payload. The attackers used iframe-hosted interchangeable content and device gating to evade analysis, and the delivery chain and artifacts strongly overlap with the Atomic macOS Stealer family.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
