Fake OpenAI Codex Downloads Deliver macOS Malware via Google Sites

Fake OpenAI Codex Downloads Deliver macOS Malware via Google Sites

First seen 25 Aug 2026, 09:46 UTC Infosecurity-MagazineTheregisterwww.catonetworks.com 59.2

Article Content

Browse articles
ThreatCluster

A malicious campaign has emerged, targeting macOS users with fake OpenAI Codex download pages hosted on Google Sites. Researchers from Cato Networks discovered that these pages trick users into executing malware disguised as installation commands. The campaign utilizes a ClickFix technique, where users are instructed to run commands in Terminal that initiate a multi-stage malware infection. The malware is designed to run on both Intel and Apple Silicon Macs, and it obfuscates its payload to evade macOS security warnings. While the fake site offered both macOS and Linux download options, malware delivery was only confirmed for macOS. The attackers have also been linked to similar campaigns targeting other AI tools, indicating a broader trend in impersonation tactics. Cato Networks has noted significant similarities to the Atomic macOS Stealer (AMOS) but has not definitively attributed the malware to AMOS. The campaign highlights the growing risk of AI-tool impersonation in cybercrime.

Key Points: • Fake Codex download pages on Google Sites trick macOS users into executing malware. • The attack uses a ClickFix technique, requiring users to run malicious commands in Terminal. • Cato Networks links the campaign to Atomic macOS Stealer but stops short of confirming it.

Timeline

2026-08-24
Cato Networks reports fake Codex download campaign
Researchers identified a campaign using Google Sites to deliver malware to macOS users via fake installation commands.
Infosecurity-Magazine
2026-08-25
The Register reports on Cato's findings
The Register published details on the malware campaign, emphasizing its targeting of Mac developers and the use of ClickFix techniques.
Theregister