Attackers Are Impersonating Claude Itself to Get Malware Onto Developer Macs
Cybersecurity

Attackers Are Impersonating Claude Itself to Get Malware Onto Developer Macs

A Google Ads and Bing redirect chain leads Mac users searching for Claude to a fake install page that swaps the copy-paste command Anthropic actually publishes for one that runs attacker code.

PublishedOctober 10, 2026
Read time5 min read
Share

The attack hides behind two legitimate-looking hops

BleepingComputer reported on October 9 that attackers are running Google search ads targeting people looking for Claude on macOS, built around a specific piece of misdirection: the ad's visible destination domain is bing.com, a real and trusted domain, which makes it look far less suspicious than a typical malicious ad display URL. Clicking it routes the victim through Google's ad redirect and then through Bing's own click-tracking endpoint, both genuine infrastructure, before Bing's JavaScript forwards the browser onward.

That forwarding lands on a compromised WordPress site belonging to a South American retailer, which then redirects again to claude-desk-code[.]com, a fake Claude download page. Security researchers at Push Security, who identified the campaign and named the technique Adception, found it after spotting a malicious Google ad specifically targeting 'claude mac' searches. The chain's design goal is clear: every hop before the final page is something a scanner, a security team, or a skeptical user would recognize as legitimate.

The payload swap is the clever part

The fake Claude page shows Anthropic's real, correct install command on screen: curl -fsSL https://claude.ai/install.sh | bash. A visitor reading the page sees exactly what they would expect from the genuine Anthropic site. But the copy button behind that displayed text puts a different command on the clipboard entirely, one that, when pasted into Terminal, decodes a Base64-encoded URL pointing to a separate malicious domain, downloads a file with curl, and pipes it directly into zsh for execution.

Two cloaking layers protect the deception from easy discovery. The compromised WordPress site checks for a Bing referrer and specific browser headers before forwarding traffic, and the fake Claude page itself runs JavaScript to confirm the visitor arrived via Google or Bing before showing the malicious version. Anyone who visits the fake domain directly, including most automated security scanners, gets routed to a plain 404 error page instead, which is precisely why this kind of campaign can run for a while before it is caught.

This is bigger than one campaign

Push Security says it identified several other domains running the identical toolkit, which it tracks under the name AcSig, all sharing the same macOS install command structure, the same payload URL pattern, and the same installer interface. That is the signature of a reusable attack kit being deployed against multiple lures, not a single bespoke operation built around Claude specifically. Today it is Claude; the same kit works against any tool whose legitimate installation flow is a copy-pasted terminal command, which describes a large share of developer tooling.

BleepingComputer's reporting does not include a confirmed victim count or identify what final payload actually runs, since the researchers have not disclosed what the piped script installs. That is a real gap in the public picture, and it means any organization that finds evidence of this chain in its logs should treat it as an active incident requiring full investigation rather than assuming it already knows the blast radius based on this reporting alone. Unknown payload plus confirmed command execution on a developer workstation is, on its own, enough to justify isolating the device and rotating any credentials it had access to while the investigation runs, regardless of what the eventual malware analysis turns up.

Why AI tool installs are a new favorite target

The copy-paste terminal install has been standard practice across developer tooling for years, and it has always carried some risk, but the current wave of AI coding tools adopted this quarter by engineering teams everywhere has sharply increased the number of people searching for and installing these tools for the first time, often on personal or lightly managed machines. That combination, high search volume for a relatively new tool plus an install flow built entirely on trust in a copied string, is exactly the setup ClickFix-style attacks are built to exploit.

It also means the clipboard itself has become an attack surface that most security awareness training has not caught up to. Employees have been trained for years to hover over links and check URLs before clicking. Almost none have been trained to verify that what they paste into a terminal matches what they saw on screen, because until recently there was little reason to think those two things could differ. This campaign is a clear signal that assumption no longer holds.

What a CTO should actually do about this

Start with a narrow, enforceable rule: engineering and IT should distribute AI tool installers through a vetted internal channel, a package manager, or a signed installer, rather than leaving developers to find and run install commands from whatever page a search ad led them to. That single change removes the entire attack chain regardless of how convincing the ad or the cloaking gets, because it takes the decision out of an individual's hands at the exact moment they are least likely to scrutinize it.

Second, update security awareness content to specifically call out clipboard manipulation and ClickFix-style terminal paste attacks, since most existing training still assumes the threat is a malicious link or attachment rather than a command that looks right on screen and runs something else. Given that Push Security found multiple domains using the same AcSig toolkit, treat this as a pattern to monitor for in your own ad and DNS telemetry, not a single incident to close out once the Claude-specific domain is taken down. Finally, loop procurement and brand teams in too: if your own company's name or product is ever searched on enough to attract the same kind of malvertising, you want to find out from your own monitoring, not from a customer who got burned by a fake installer wearing your logo.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#malvertising#social-engineering#macos#developer-security#push-security#adception#clickfix-campaign#claude-impersonation