Product1 distinct publisher3 min readUpdated
Cato says a sponsored result for "codex macos download" leads to a Google Sites clone whose Terminal command strips quarantine flags and stages an AMOS-linked payload.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
Every surface the victim touches before the malware lands belongs to someone with a good reputation. The entry point is a paid Google search result that sits above OpenAI's own listing for queries such as "codex macos download" [2]. The landing page is on Google Sites and reproduces the Codex download portal down to the macOS and Linux buttons [3]. The attacker's live content arrives inside an iframe that Cato says is probably routed through a Google static-content proxy [4]. Count the hops and three of them are Google-operated properties [1].
That last one is the operational detail. Cato found no malicious code on the Google Sites page itself, so the page a reviewer inspects can stay unchanged while the ClickFix instructions behind the iframe are swapped out [4]. The lure is decoupled from the hosting reputation it borrows.
The command the page asks for opens with a plausible npm install string for Codex, then decodes a Base64 URL and pipes a retrieved script into zsh [6]. Stage one is padded with dead code and unused variables around an encoded blob it hands to eval, and stage two's first act is a request to an attacker endpoint carrying event=pasted [7]. That is conversion tracking. The operators learn how well the lure copy performs before they learn whether the payload ran.
What follows is ordinary. The script pulls the final payload to /tmp/helper, runs xattr -c to clear its extended attributes, makes it executable and launches it, and clearing those attributes removes the download quarantine metadata that would normally put a warning in front of the user [8]. Nothing was exploited. The user supplied the privilege by typing past it. Cato ties the framework to Atomic macOS Stealer on loader URL structure, the telemetry request, the /tmp/helper staging path, the attribute removal and update-themed payload URLs, calling the match strong without naming the final binary [10][11]. It ships as a universal Mach-O, so Apple Silicon is no barrier [11].
The evasion is aimed at whoever checks. The live ClickFix page sits at /codexx/ while the obvious /codex/ path returns a harmless product page, and non-macOS visitors are served benign content too [5]. An analyst who guesses the intuitive URL, or looks from a Linux box, sees a clean site. Cato's own conclusion is that no single stage reliably exposes the attack and detection depends on correlating search delivery, embedded content, Terminal execution and outbound activity [14]. That is four telemetry sources to join, on the one class of endpoint where pasting shell commands is routine work.
Cato notes that several campaigns this year have dressed delivery in AI developer tooling [15]. The artifact worth controlling is the install instruction itself: if the canonical command for a tool lives in an internal document and nowhere else, a search ad has nothing to sell. Blocking hosts is the slower track. The loader has already been reworked between infrastructure sets, with early samples compressing and Base64-encoding the second stage and newer ones using an AES-encrypted gzip container whose key is rebuilt from variables scattered through the script [9], and Cato says it blocked the reused iframe host while the operators keep rotating domains and payload locations [13].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The Google Sites page carries no malicious code of its own; attacker content loads inside an iframe, probably routed through a Google static-content proxy, and the split lets operators refresh the ClickFix content without touching the Google Sites page victims see.
Cato Networks' Cato CTRL threat research team detailed a macOS attack campaign built around a fake OpenAI Codex installer, ending with the victim opening Terminal and pasting a command that runs the malware, the social engineering pattern known as ClickFix.
The campaign begins with a sponsored Google search result for queries such as "codex macos download"; the ad sits above OpenAI Group PBC's own listing.
Clicking the ad leads to a page on Google Sites that copies the Codex download portal, down to the macOS and Linux buttons; Cato observed payload delivery only for macOS.
Cato mapped three infrastructure sets; the live ClickFix page sits at /codexx/ while the more obvious /codex/ path returns a harmless product page, and non-macOS visitors were served benign content, so an analyst or scanner requesting the intuitive path may never be served the attack.
The fake installer walks the user through opening Terminal and pasting a command that starts with a plausible npm install string for Codex, then decodes a Base64 URL and pipes a remotely retrieved script into zsh.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-vendor and unverified
The technical account is unusually concrete for one article - named paths (/codexx/, /tmp/helper), a specific command (xattr -c), a named telemetry parameter (event=pasted), three mapped infrastructure sets and a described loader change from Base64 compression to an AES-encrypted gzip container. All of it rests on one vendor report relayed by one outlet, with no indicator list, no independent confirmation, and an attribution the researchers themselves hedge as consistent-with rather than confirmed. The only external touchpoint is Microsoft's separately documented macOS ClickFix operation, cited as context.
Live campaign, unquantified reach
Real-world activity is established rather than hypothetical: the malicious ad outranked OpenAI's own listing, three infrastructure sets were mapped, the operators were still rotating domains and payload locations at publication, and a related macOS ClickFix operation was documented separately by Microsoft. What is entirely absent is scale - no victim counts, no beacon volumes despite the campaign's own event=pasted telemetry, and no geographic or sector spread - so reach cannot be scored higher than 'confirmed operational'.
Slightly overstated framing, hedged substance
The framing leans on the striking detail that a fake installer outranked OpenAI in ads, and the AMOS name carries more alarm than the underlying finding supports - the researchers matched delivery-framework artefacts, not the final binary. Against that, the article preserves the vendor's own hedges, quotes the limitation that no single stage reliably exposes the attack, and avoids claiming victim numbers it does not have, so the gap is modest rather than severe.
Vendor research with commercial upside
The findings originate with a security vendor's in-house threat research team, and the write-up includes the vendor's statement that it has blocked the reused iframe host and continues tracking the operators - a capability demonstration alongside the disclosure. The concluding advice that detection requires correlating search delivery, embedded content, Terminal execution and outbound activity maps directly onto the kind of converged platform such a vendor sells. This is standard practice rather than evidence of distortion, but it is a material incentive with no counterweight from Google, OpenAI or an independent researcher in this cluster.
Coherent single-source account
The chain described is internally consistent and technically plausible, and the specificity of paths, commands and telemetry parameters makes fabrication unlikely. Confidence is held below high because the cluster contains one publisher relaying one vendor, the attribution is explicitly partial, the scale of the campaign is unknown, and the platforms whose surfaces were abused were not heard from.
build
Grok 4.6 lands in Copilot two days after launch, and the model picker becomes a procurement problem1 distinct publisher
product
Washington's secret AI test is coming for open weights, and release dates go with it2 distinct publishers
product
The AI-wrote-it claim died in eight hours. The Actions injection pattern did not.1 distinct publisher
invest
Microsoft's Idle AI Chips Are A Construction Problem, Not A Shortage1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026