SECURITY Signal 56
Fake OpenAI Codex Google ads push ClickFix Mac malware via Terminal commands
Malicious Google-sponsored search results for OpenAI Codex direct Mac developers to fake download pages that trick them into pasting malware installation commands into Terminal.
Developers actively searching for AI coding tools are targeted through legitimate ad infrastructure, making the social engineering more convincing. The ClickFix technique bypasses traditional malware delivery by having victims execute commands themselves, and the malware strips macOS security markers to avoid detection.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Sponsored Google search results for OpenAI Codex lead to fake Google Sites pages that instruct users to paste malicious commands into Terminal.
The malware delivers universal Mach-O binaries compatible with both Intel and Apple Silicon Macs and removes macOS quarantine flags to evade warnings.
Cato Networks found the campaign shares infrastructure with a similar ClickFix page targeting Anthropic's Claude Code and shows substantial similarities to the AMOS infostealer.
THE CLUSTER