Malicious Google Ads Hijack ChatGPT Links to Spread Mac Stealer Malware
cyb3rops · x · 2026-08-11
Security researchers have uncovered a new malware distribution chain targeting Mac users. Attackers purchase Google Search ads to place a spoofed link at the top of search results.
Clicking the ad directs victims to a legitimate ChatGPT shared conversation page. This page uses a friendly tutorial tone to trick users into opening the Terminal and pasting a command. This command contains a hidden base64 encoded script that downloads the MacSync Stealer malware from a known malicious domain, compromising passwords, keychains, and crypto wallets.
The attack requires no system exploit, relying entirely on users' trust in Google Ads and the official ChatGPT domain. Users are advised never to execute Terminal commands sourced from web ads or unfamiliar chat pages.
More from Safety
- AI safety eval controversy: Israeli startup Irregular linked to 'rogue AI' incidents at OpenAI, Anthropic, Meta — nptacek · 2026-08-11
- EU AI Act Won't Force 'AI Generated' Labels on All Blogs: SEO Misconceptions Clarified — gaganghotra_ · 2026-08-11
- Testing Claude Operating Social Media Inboxes with Real Write Permissions via MCP — Purple_Network3016 · 2026-08-11
- ComfyUI Instance Hacked for Crypto Mining via Public IP Exposure — slpreme · 2026-08-11
- DeepSeek v4 flash jailbreak exposed: role-playing prompts bypass safety guardrails — aaditya_ai · 2026-08-11
- OpenAI Sends Letter to Texas Governor on Responsible AI Infrastructure — ArtificialOther · 2026-08-11