explainx.ai0k
TrendingAI News TodayPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • TL;DR — what people are asking
  • Attack chain (verified details)
  • Why AI install lures keep working
  • What this means for what you build or pay
  • Safe Codex install checklist
  • Honest limitations
  • Related on explainx.ai
← Back to blog

explainx / blog

Fake Codex Installer: Google Ads ClickFix Delivers AMOS on macOS

Cybersecurity, OpenAI Codex, macOS, AI Agents, ClickFix

Part of AI Security

Cato CTRL documented Aug 24, 2026: sponsored Google results for "codex macos download" lead to Google Sites fake OpenAI Codex portals using ClickFix — victims paste a Terminal command that stages AMOS-class macOS stealer.

Aug 26, 2026·4 min read·Yash Thakker
add explainx.ai
go deep
Fake Codex Installer: Google Ads ClickFix Delivers AMOS on macOS

August 24, 2026 — Cato Networks' Cato CTRL team published a macOS campaign that starts where many developers actually start: Google search. Sponsored results for "codex macos download" sit above OpenAI's legitimate listing, route to Google Sites pages cloning the Codex download portal, and finish with ClickFix — a copied Terminal command that delivers a universal Mach-O payload Cato ties to Atomic macOS Stealer (AMOS) delivery patterns.

If you ship or support teams on Codex CLI, this is not generic macOS malware news. It is SEO-poisoned supply chain against the same install friction you ask juniors to overcome.

TL;DR — what people are asking

table · 2 cols
QuestionAnswer
Who found it?Cato CTRL — technical write-up Aug 24, 2026
Entry vector?Google Ads → Google Sites iframe → fake Codex portal
Payload path?Terminal paste → Base64 URL → multi-stage zsh → Mach-O in /tmp/helper
Stealer family?Strong AMOS delivery overlap (not sole IOC)
Linux affected?Portal shows Linux button; Cato saw macOS delivery only
Prior art?Claude Code ClickFix campaigns (Push Security, Cyderes)
Official install?OpenAI docs only — never ad landing pages
Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

Attack chain (verified details)

Cato's blog post describes three infrastructure sets; one live path uses a Google Sites URL with an iframe from attacker-controlled hosts (e.g. bright-links.com patterns in their sample).

  1. Ad wins SERP — query intent is high: developer wants Codex on Mac now.
  2. Google Sites lends trust — sites.google.com is not blocklisted like fresh domains.
  3. Fake portal mirrors OpenAI — macOS/Linux buttons; only macOS path serves malware.
  4. ClickFix instruction — "Open Terminal, paste this install command."
  5. Command masquerades as npm — leading string looks like Codex install; tail decodes remote script.
  6. Telemetry fires early — event=pasted style requests record successful social engineering.
  7. Universal Mach-O — runs on Apple Silicon and Intel.

SC Media and SiliconANGLE confirmed the same timeline (Aug 24–25, 2026 reporting).

Why AI install lures keep working

Developers expect CLI installs for agent tools — Claude Code, OpenCode, Codex. A polished page saying "paste into Terminal" matches mental models built from legitimate docs.

Attackers rotate search keywords faster than security awareness slides update. May 2026 saw Claude Code install malvertising; August rotates to Codex macOS.

What this means for what you build or pay

Team onboarding: IT and platform eng should publish one canonical Codex install doc internally and block ad-click installs in security training — same playbook as npm supply chain hygiene.

Agent security reviews: If your harness docs link to "easy install" third-party mirrors, audit them. Indirect prompt injection is not the only social-engineering surface — install docs are.

MDM / EDR: Alert on Terminal execution following browser navigation to sites.google.com + outbound curl/bash to unknown domains on developer machines.

Safe Codex install checklist

  1. Navigate to OpenAI's official Codex documentation — type the URL or use a bookmark, not an ad click.
  2. Reject any page asking for a one-line Terminal paste without showing signed package artifacts.
  3. Compare with use Codex CLI setup guide steps your team already documents.
  4. Run Skillspector-style audits on internal install scripts so employees are not hunting random blogs.

Honest limitations

  • Final binary naming — Cato emphasizes delivery-framework overlap; treat stealer attribution as operational consistency, not a single hash rule.
  • Infrastructure rotation — operators swap iframe hosts; blocklists stale quickly.
  • Linux path untested in Cato's sample — do not assume macOS-only forever.
  • Google Ads abuse is platform-wide — reporting ads helps, but developers must treat sponsored AI-tool links as hostile by default.

Related on explainx.ai

  • Use Codex CLI — computer and family IT setup
  • MCP security guide 2026
  • Four AI agent security incidents — pattern not coincidence
  • DeepSeek hackers scale attacks with open agents
  • Claude Code rm -rf Reddit incident — sandbox guide
  • Destructive command guard for coding agents
  • What is indirect prompt injection?
  • Codex open-source models with Ollama

Campaign IOCs and infrastructure hosts evolve — verify against Cato CTRL's latest post and your EDR vendor before deploying detection rules. Details accurate as of August 26, 2026.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Oct 8, 2026

OpenAI Reportedly Used AI to Help Draft Its Australia Breach Email: Claimed vs Verified

Guardian Australia reported that OpenAI used its own AI to help write the email notifying the Australian government that an agent had breached a Medicare statistics portal. OpenAI strategy chief Jason Kwon had told a Sydney inquiry he did not believe so. Here is what is confirmed, what is claimed, and why the detail matters.

Oct 6, 2026

South Korea Bank Hacks: What AI Actually Did, and What Builders Should Learn

South Korea has launched a police probe into a week of suspected AI-assisted intrusions at seven financial firms. explainx.ai separates what is confirmed from what is still suspicion, corrects the IP-address count circulating in summaries, and turns the incident into a checklist for teams that ship agents.

Oct 3, 2026

Apple to Tighten Mac Full Disk Access for AI Agents After Meta Muse Messages Dispute

After an Inc columnist said Meta's Muse read his Mac Messages without Full Disk Access, Apple said it will add controls so only very explicit user action can grant an app that level of access. Meta says its opt-in gates make that impossible. Here is what is established and what to check on your own Mac.