Fake Codex installer tricks Mac users into pasting malware, Cato finds

Cato Networks Ltd.’s Cato CTRL threat research team today detailed a macOS attack campaign built around a fake OpenAI Codex installer.

The lure ends with the victim opening Terminal and pasting a command that runs the malware, the social engineering pattern known as ClickFix.

It begins with a sponsored Google search result for queries such as “codex macos download.” The ad sits above OpenAI Group PBC’s own listing. Clicking it leads to a page on Google Sites that copies the Codex download portal, down to the macOS and Linux buttons. Cato observed payload delivery only for macOS.

That Google Sites page carries no malicious code of its own. Attacker content loads inside an iframe, probably routed through a Google static-content proxy. The split lets the operators refresh the ClickFix content without touching the Google Sites page victims actually see.