security
Crooks push Mac malware through fake OpenAI Codex ads
Sponsored search results lead developers straight into a ClickFix malware trap
The Register
Publisher
Aug 25, 2026 at 9:15 AM UTC · 2 分で読める

Crooks push Mac malware through fake OpenAI Codex ads
Sponsored search results lead developers straight into a ClickFix malware trap
Cybercrims are using fake OpenAI Codex download pages to trick Mac developers into running malware disguised as installation commands.
Researchers at Cato Networks uncovered the campaign after spotting sponsored Google search results targeting people looking to download Codex for macOS. The ads direct would-be users to a convincing-looking download page hosted on Google Sites, complete with the familiar OpenAI branding. There is, however, no Codex waiting at the other end.
Instead of serving up an installer, the fake site tells Mac users to open Terminal, paste in a supplied command, and run it. The instructions are dressed up as part of the installation process, but the command quietly kicks off a multi-stage malware infection.
It's a variation of the increasingly popular "ClickFix" technique, in which attackers convince victims to execute malicious commands themselves rather than relying on a dodgy attachment or executable to do the dirty work.
In this case, the command begins with what appears to be a legitimate npm instruction for installing Codex. Tacked onto it, however, is code that decodes a Base64-encoded URL, fetches an attacker-controlled shell script and pipes it into zsh.
Article Intelligence
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
