Back Malware-Traffic-Analysis 2026-10-02: Atomic macOS (AMOS) Stealer infection from malicious ad impersonating Claude Code
2026-10-02 (FRIDAY): ATOMIC MACOS (AMOS) STEALER INFECTION FROM MALICIOUS AD IMPERSONATING CLAUDE CODE
Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the " " page of this website.
22.8 MB (22,798,871 bytes)
1.3 MB (1,256,365 bytes)
Shown above: Malicious ad impersonating Claude Code.
Shown above: Malicoius site impersonating Claude Code.
Shown above: ClickFix style instructions pretending to install Claude Code but actually installing AMOS Stealer.
Shown above: ClickFix style script for AMOS Stealer pasted into a macOS Terminal window.
Shown above: Popup requests for password and permissions requested by AMOS Stealer.
to return to the main page.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
