Wednesday, August 26, 2026

Some Mac users think they’re installing OpenAI Codex, but it’s actually a malware that can steal passwords in seconds


  • Crooks used Google Sites and stolen Google Ads accounts to push fake OpenAI Codex pages
  • macOS users tricked into pasting Terminal commands, leading to AMOS infostealer infection
  • Campaign abuses Google’s trust signals; Windows download button was a decoy, only Mac payload worked

Cybercriminals were seen abusing Google Sites, the Google ad network, and OpenAI’s good name, in a campaign that targets macOS users with infostealers.

According to security researchers CATO CTRL, the crooks used Google Sites to create a fake version of the OpenAI Codex download site. To avoid being flagged by Google’s security systems and ultimately removed, the site itself contains no malicious code or download links, whatsoever. Instead, it hosts an iFrame that displays content hosted elsewhere.

Related Articles

Latest Articles