WorkAugust 24, 2026via SiliconAngle

Fake Codex installer tricks Mac users into pasting malware, Cato finds

Why it matters

AI tools are becoming attack surface. As developers adopt Codex, Claude, and other code-generation products, threat actors are weaponizing them as social engineering lures—targeting the exact audience most likely to trust and install them quickly.

Key signals

  • Fake OpenAI Codex installer discovered in sponsored Google search results
  • Attack uses ClickFix pattern: social engineering victims into pasting terminal commands
  • Cato Networks CTRL team attributed the campaign
  • Targets macOS users searching for Codex
  • Malware deployed via command-line execution after credential harvesting
  • Attack vector: fake OpenAI Codex installer via sponsored Google search results
  • Social engineering method: ClickFix (victim opens Terminal and pastes malicious command)
  • Target: macOS users, likely developers
  • Source: Cato Networks CTRL threat research team
  • Date: August 24, 2026

The hook

Attackers are now spoofing AI developer tools. A fake Codex installer is luring engineers into pasting malware via Google search ads.

Cato Networks Ltd.’s Cato CTRL threat research team today detailed a macOS attack campaign built around a fake OpenAI Codex installer. The lure ends with the victim opening Terminal and pasting a command that runs the malware, the social engineering pattern known as ClickFix. It begins with a sponso

The week's key stories, every Friday.

ONE BRIEFING · EVERY FRIDAY · FREE

Free. Unsubscribe anytime.