UNCOS

Search Uncos

Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds

Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds

image via TechRadar

August 25, 2026, 12:35 PM

  • Researchers at Cato CTRL said attackers abused Google Sites, Google Ads, and OpenAI branding in the campaign.
  • The malicious ads reportedly appeared for searches such as "codex macos download" and were placed at the top of results.
  • The fake site offered Windows and Mac download buttons, but only the Mac path functioned.
  • The installation flow told targets to paste a command into Terminal to make the process seem legitimate.
  • AMOS is described as a macOS infostealer that can collect browser data, login credentials, and crypto wallet details.

Cybercriminals used Google Sites and Google Ads to promote a fake OpenAI Codex download page aimed at macOS users. The landing page itself reportedly avoided hosting malicious code directly and instead displayed externally hosted content through an iFrame. Victims who clicked the ad were shown a convincing download site and instructed to paste a command into Terminal rather than run a normal installer. According to Cato CTRL, the campaign’s goal was to install the AMOS infostealer, which can steal browser data, credentials, and cryptocurrency wallet information.

Read original article

Entities Mentioned

Sead Fadilpašić

Topics Covered

SecurityCyber SecurityComputing SecuritymacOSProComputingSoftwareCybersecurityMacOSMalwareGoogle AdsOpenAI

Comments (0)

No comments yet.