FAKE OPENAI CODEX ADS TARGET MAC USERS WITH MALWARE
Cybercriminals used Google Sites and stolen Google Ads accounts to distribute malware to macOS users through fake OpenAI Codex download pages, according to security researchers at Cato Networks. The campaign displayed sponsored ads targeting searches for "codex macos download", directing users to a counterfeit download site hosted on Google Sites that mimicked OpenAI's branding. The fake site contained no malicious code itself but used an iFrame to display content hosted elsewhere, allowing it to evade Google's automated security systems.
Users who clicked the ads encountered download buttons for both Windows and macOS, though only the macOS version functioned. Rather than providing an executable installer, the site instructed users to open Terminal and paste a command, disguised as a legitimate installation process. The command appeared to be an npm instruction for installing Codex but contained additional code that decoded a Base64-encoded URL, fetched an attacker-controlled shell script, and executed it through zsh. The malware then removed security information that macOS uses to flag suspicious downloads before launching the final payload.
Security researchers identified the final malware as substantially similar to Atomic macOS Stealer, commonly known as AMOS, an infostealer capable of extracting browser data, login credentials, and cryptocurrency wallet information. Cato Networks determined the malware was compiled as universal Mach-O files, allowing it to run natively on both Intel-powered Macs and newer Apple Silicon machines. The campaign represents a variation of the ClickFix technique, in which attackers convince victims to execute malicious commands themselves rather than relying on traditional malware delivery methods.