Sponsored Google ad for fake OpenAI Codex served Base64-hidden stealer via curl|zsh

thezyzz · reddit · 2026-08-17

A user searching Google for OpenAI Codex clicked the top sponsored result, which appeared to link to Google but led to a Google Pages-hosted fake install guide. The instructions wrapped a legitimate-looking npm install echo around a Base64-encoded URL that was decoded and piped into zsh, downloading and executing a remote payload from an unrelated server.

The author's post-incident checks found no persistence (no rogue LaunchAgents, shell config changes, or suspicious processes), and his real Codex install via Homebrew was verified as signed by OpenAI OpCo, LLC. His main worry is a one-shot infostealer that may have exfiltrated Chrome passwords/cookies, Keychain data, SSH keys and API tokens. Takeaway: a legit-looking echo prefix means nothing—always verify you're on an official OpenAI source before pasting into Terminal.

Original post →

More from Safety

Safety channel →