Sponsored Search Drives Fake Codex Mac Malware

Cato Networks said on August 24 that a fake OpenAI Codex download campaign used sponsored search results and Google Sites pages to push a macOS-only malware chain. The lure caught people searching for phrases like “codex macos download,” then led them to a Google Sites page that looked like a download portal. The page did not hand over a normal file. It showed ClickFix-style instructions that told the user to open Terminal and paste a command; that command decoded a URL, fetched a shell-script loader, and ultimately retrieved the Mac payload. The Google Sites front end and iframe-delivered content made the hosting look familiar while the malicious action happened only after the paste. That means web reputation alone can miss the real handoff from search result to shell execution. If users in your environment trust sponsored links and paste installer commands, the exposure sits across search, browser, and endpoint telemetry, not just on the hosting domain.

Part of the PlainSec briefing for 2026-08-25

Editions

Sources