logo

ClickFix Attack Targets Devs with MacSync Malware via Fake Claude Tools

ID: 635410c9-9543-5e24-8bed-508ba39bc7ce

STIX ID: report--635410c9-9543-5e24-8bed-508ba39bc7ce

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

A campaign named "Claude Fraud" uses convincing sponsored Google ads and fake AI/tool pages (including pages hosted on claude.ai and Squarespace) to deliver macOS and Windows malware: MacSync (macOS) and fake VS Code plugins leading to CrossMark2. Victims who execute provided commands or install plugins have had Keychain credentials, browser cookies and crypto-wallet keys stolen; attackers also use PowerShell to exclude folders from antivirus and have abused stolen advertising accounts to distribute the ads. Researchers report over ~15,600 victims and emphasize checking sources before running tools or plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.