Fake Codex Installer Delivers Suspected AMOS Infostealer via Google Sites

Fake Codex Installer Delivers Suspected AMOS Infostealer via Google Sites

First seen 25 Aug 2026, 09:46 UTC Infosecurity-MagazineTheregisterGround.NewsScworldFeeds2.Feedburner+4 64.5

Article Content

Browse articles
ThreatCluster

A malicious campaign has emerged, using fake Codex installation pages to deliver malware targeting macOS users. The attackers utilize Google Sites to host a fraudulent download portal that appears legitimate, tricking users into executing a command that initiates a multi-stage malware infection. The command, disguised as a legitimate installation process, retrieves a shell script that ultimately downloads a Mach-O binary suspected to be the Atomic macOS Stealer (AMOS). Cato Networks identified multiple infrastructure sets and obfuscation techniques used in this campaign, including path-aware content serving to evade detection. The malware is designed to run on both Intel and Apple Silicon Macs, with significant similarities to known AMOS campaigns. The campaign is ongoing, with researchers advising caution to users searching for AI coding tools.

Key Points: • Fake Codex download pages are used to deliver malware to macOS users. • The attack employs ClickFix techniques to obfuscate malicious content within trusted domains. • The final payload is suspected to be the Atomic macOS Stealer (AMOS), targeting both Intel and Apple Silicon Macs.

Timeline

2026-08-24
Cato Networks reports fake Codex download campaign
Researchers identified a campaign using Google Sites to impersonate an OpenAI Codex download portal, targeting macOS users.
Infosecurity-Magazine
2026-08-25
Scworld reports on ClickFix techniques
Cato Networks detailed the use of ClickFix methods to deliver malware via a fake Codex installation page, highlighting its sophistication.
Scworld
2026-08-25
The Register covers ongoing malware campaign
The Register reported on the ongoing campaign, emphasizing the use of Google Sites and the multi-stage infection process targeting Mac developers.
Theregister