Malicious Google Ads Hijack ChatGPT Links to Spread Mac Stealer Malware

cyb3rops · x · 2026-08-11

Security researchers have uncovered a new malware distribution chain targeting Mac users. Attackers purchase Google Search ads to place a spoofed link at the top of search results.

Clicking the ad directs victims to a legitimate ChatGPT shared conversation page. This page uses a friendly tutorial tone to trick users into opening the Terminal and pasting a command. This command contains a hidden base64 encoded script that downloads the MacSync Stealer malware from a known malicious domain, compromising passwords, keychains, and crypto wallets.

The attack requires no system exploit, relying entirely on users' trust in Google Ads and the official ChatGPT domain. Users are advised never to execute Terminal commands sourced from web ads or unfamiliar chat pages.

Original post →

More from Safety

Safety channel →