ixsoftum
AI-assisted development

Fake OpenAI Codex ads push Mac malware via ClickFix

Published 26 Aug 2026, 10:04 UTC
Ava Harlan
Ava HarlanStaff writer
Share
Fake OpenAI Codex ads push Mac malware via ClickFix

Cybercriminals are buying sponsored Google results for searches like "codex macos download" and routing macOS developers to fake OpenAI Codex install pages built on Google Sites, according to Cato Networks, which discovered the campaign.

The fake page skips a malicious attachment entirely. Instead it tells the visitor to open Terminal, paste a supplied command, and run it as part of "installation," a technique known as ClickFix that gets the victim to trigger the infection themselves. The command opens looking like a normal Codex npm install line, then quietly decodes a Base64-encoded URL and pipes a remotely fetched script into zsh. Later stages download further payloads, strip the extended attributes macOS uses to flag untrusted files, and run a universal Mach-O binary that works on both Intel and Apple Silicon.

Cato found the delivery chain closely resembles Atomic macOS Stealer (AMOS), an established macOS infostealer, matching details down to the telemetry endpoint and staging directory, though it stopped short of calling it a confirmed AMOS variant. The fake portal also listed a Linux download option, but researchers only observed an active payload for macOS.

The practical lesson is how convincingly the ad and install steps were built to look legitimate at every stage. A sponsored result outranking the real openai.com listing carries no trust of its own, and no genuine coding-tool installer asks you to copy a Terminal command off a landing page. Install Codex and similar tools from the official npm package or openai.com directly, and treat any "paste this into Terminal" install step as a stop sign, no matter how polished the page around it looks.