Fake “OpenAI Codex” Ads Push Mac ClickFix Malware

The Register Security · Medium sophistication
Last updated August 25, 2026

Attackers are buying sponsored Google search ads that send Mac developers to fake OpenAI Codex download pages. The pages instruct victims to paste a Terminal command that looks like a normal install step, but actually downloads and runs a multi-stage malware payload.

Key findings

  • Sponsored Google search ads lead to a convincing fake OpenAI Codex download page hosted on Google Sites.
  • Victims are instructed to open Terminal and run a pasted command as part of a supposed install process (ClickFix-style).
  • The command decodes a Base64 URL, fetches an attacker shell script, and pipes it into zsh, leading to a multi-stage infection.
  • Later stages download a Mach-O payload to "/tmp/helper" and attempt to remove macOS security metadata used to flag suspicious downloads.
  • The campaign appears similar to Atomic macOS Stealer (AMOS) distribution patterns, though Cato did not fully attribute it.

Who’s being targeted

  • Commonly targeted roles: Developers, Engineering, DevOps, IT.
  • Affected industries: Software development, Technology, Professional services.
  • Attack channels: website.
  • Impersonated: OpenAI Codex download page (OpenAI branding) hosted via Google Sites, Legitimate npm-based Codex installer instructions.

Awareness takeaways

  • Treat sponsored search results for downloads as untrusted and navigate to the vendor’s official site directly.
  • Be suspicious of any ‘installation’ process that asks you to paste and run Terminal commands from a website.
  • Watch for obfuscation and risky command patterns (Base64 decoding, curl/wget, piping into a shell) as strong indicators of malicious intent.
  • Assume lookalike branding and reputable hosting platforms can still be used to deliver attacks; verify the exact domain and source.

Red flags to watch for

  • Sponsored search ad redirects to a non-official hosting location (Google Sites) for a software download
  • Site asks user to run a pasted Terminal command instead of providing a normal installer
  • Command includes obfuscated content (e.g., Base64 decoding) and pipes to a shell
  • Install command has extra appended code beyond a typical npm install
  • Uses Base64 decoding and fetches a remote script
  • Pipes downloaded content directly into zsh
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You Google “OpenAI Codex download for macOS” and click the top result, looks legit, OpenAI logo and all. But that click lands you on a Google Sites page impersonating the Codex download. Instead of a normal installer, it says: “Install Codex for macOS: open Terminal and paste the following command to complete installation.” The command looks like a normal npm install, but tacked on is obfuscated Base64, curl, and a pipe into zsh, quietly pulling a Mach-O payload into /tmp/helper and stripping macOS security flags. One paste, multi-stage infection. If any website tells you to paste a long install command into Terminal, stop. Instead, go directly to openai.com yourself and only follow install steps from there.

Similar attacks

Fake Codex Ad Tricks Mac Users to Paste Malware

Fake Codex Ad Tricks Mac Users to Paste Malware

Attackers used a sponsored search ad to send macOS users to a fake “OpenAI Codex download” page hosted on Google Sites. The page convinced victims to open Terminal and paste a command that secretly downloaded and ran a multi-stage malware infection.

August 25, 2026
Google Doc “Fix” Trick Delivers Malware

Google Doc “Fix” Trick Delivers Malware

A real-world social engineering attempt used a legitimate Google Doc to trick a target into manually running commands that installed malware. The attacker posed as a crypto marketing executive and used a fake “decryption failure” message and a “manual update” button as the lure, leading to an…

September 21, 2026
Phishing Gets Smarter: QR Codes, Tokens, Deepfakes

Phishing Gets Smarter: QR Codes, Tokens, Deepfakes

The article describes how real-world phishing and social engineering are evolving to bypass the checks employees are trained to use (bad grammar, suspicious URLs, obvious fake login pages). It highlights specific, observed attack workflows including QR-code “device hop” phishing, OAuth token theft…

September 29, 2026
Fake ChatGPT Invoice Email Steals Logins

Fake ChatGPT Invoice Email Steals Logins

Attackers are sending fake ChatGPT billing emails that pressure people to “update payment” within 48 hours to avoid service interruption. The message links to a convincing look‑alike ChatGPT login page via a Google redirect, aiming to steal OpenAI credentials.

September 18, 2026
Prompt Injection Steals Agent Vault Secrets

Prompt Injection Steals Agent Vault Secrets

Unit 42 showed that default AWS AgentCore Harness settings can let an attacker use prompt injection to trick an AI agent into running shell commands and exposing plaintext credentials from AgentCore Identity at runtime. In their demo, a malicious support ticket embedded instructions (via hidden…

September 18, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026