Skip to main content

Morning Overview

Fake Claude download ads on Google are tricking Mac users into running a malicious command

A Google search for “claude mac” on or around October 5, 2026 could return a sponsored result that displayed bing.com as its web address and ended at a counterfeit Claude download page. The page showed the genuine one-line install command for Anthropic’s tool, but the Copy button put a different command on the clipboard. Pasted into Terminal, that command pulled a script from an attacker-controlled server and fed it straight to the Mac’s zsh shell.

Push Security, which spotted the ad inside a customer environment, published the chain on October 9, 2026 and named the redirect trick “Adception.” The payload at the end was still unidentified when BleepingComputer reported it the same day.

Four hops from a Google ad to a fake download page

According to Push Security’s write-up of Adception, the sponsored result first passed through Google’s own ad-click redirect, then landed on bing.com/ck/a, the click-tracking endpoint Bing uses for ordinary search results. The real destination sat base64-encoded in the link’s u parameter. A timestamp inside that link points to October 5, 2026 as the day it was generated.

Bing forwards visitors with a short JavaScript page rather than an HTTP redirect, so the request returns a normal 200 response and the next site in the chain sees a bing.com referrer. That detail matters to the attacker: the hop after Bing was a real, search-indexed company-profile page on a South American homeopathy retailer whose WordPress site had been compromised. Push says the authors know of no earlier public report of Bing’s redirect being used as the landing target of a search ad.

The compromised page only forwarded visitors who arrived with a Bing referrer and matching browser headers. The last stop, claude-desk-code[.]com, ran its own JavaScript check of document.referrer and sent anyone who had not come from Google or Bing to a 404 page. A researcher pasting the lure address into a browser would therefore see nothing, which is why the campaign is hard to find with automated scanners.

The swapped clipboard command

The lure page imitated Claude’s macOS download screen, complete with a “Download for macOS” button and a boxed install line. The line on screen was Anthropic’s legitimate installer, which fetches claude.ai/install.sh and pipes it to bash. What reached the clipboard was something else. BleepingComputer’s account says the substituted command first prints text claiming a download from Anthropic’s official site, then decodes a hidden base64 URL pointing at lake-90[.]com, silently pulls a .dat file with curl and pipes the contents into zsh.

Because the Terminal output echoes a genuine-looking Claude address both times, a victim who checks the page and then glances at the window sees nothing out of place. This is the pattern researchers call ClickFix, or InstallFix when the bait is a software installer: the victim, not an exploit, runs the code, so no browser vulnerability is needed and the malware is never written to disk first. Push notes that the downloaded content goes straight into zsh, so nothing is saved to disk, and BleepingComputer adds that the Terminal window shows the legitimate Claude URL even though a different script is running.

An AcSig toolkit and a crowded field of Claude lures

Push links claude-desk-code[.]com to a ClickFix toolkit it tracks internally as AcSig. Other lure domains in its indicator list, among them cli-desktop[.]com, fairpoint29[.]com and turbowave45[.]com, share the same macOS command, the same payload URL pattern and the same install-modal code. The firm also lists the ad’s campaign ID, 24303361122, which Google’s abuse teams can use to trace the account behind it.

The campaign is not the first to borrow Claude’s name. Malwarebytes reported on May 12, 2026 that sponsored results for “Claude Mac download” led to real Claude shared chats dressed up as official Mac guides, and that the pasted command ran through osascript to deliver an infostealer. Bitdefender Labs documented a March 11, 2026 wave in which fake Claude Code documentation hosted on a Squarespace subdomain handed Windows users an mshta.exe command and Mac users a base64 curl command piped into zsh.

Push’s wider tally explains the repetition: in its October 9 analysis of AI-themed attacks, the firm says ClickFix detections now exceed half of its monthly total, and four in five ClickFix pages it intercepted were reached from a search engine.

Telling the real installer from the copy

Push Security says its own clipboard detection flags the malicious copy event no matter which page delivers it, and that its customers needed no further action. For everyone else, the practical tell is where the instruction came from. Anthropic’s installer command is meant to be copied from the company’s own documentation, reached by typing the address or using a bookmark rather than clicking a sponsored result. Malwarebytes recommends typing commands by hand instead of pasting them and notes that macOS Tahoe 26.4 and later warns about possible ClickFix attacks.

The unresolved piece is what lake-90[.]com served. Neither Push nor BleepingComputer says whether the .dat file was an infostealer, a backdoor or something else, and the site refuses direct visits.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview


Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.