← Home
CYBERSECURITY

Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds

August 27, 2026 Priya Nair

AMOS has been active in cybercriminal circles

A deceptive campaign targeting macOS users has been uncovered, where fake versions of OpenAI Codex are distributed through malicious Google Sites and compromised Google Ads accounts. The scheme, identified in late August 2026, tricks users into downloading AMOS, a known infostealer malware capable of extracting passwords and sensitive data within seconds of execution. Security researchers at ProSecurity first detected the operation after noticing a spike in suspicious downloads linked to AI tool impersonations. The attackers created convincing replicas of legitimate OpenAI Codex download pages, hosting them on Google Sites to appear trustworthy. By hijacking Google Ads accounts, they promoted these fake pages in search results, increasing visibility to users searching for AI coding assistants. Once downloaded, the malware runs silently in the background, harvesting login credentials, browser data, and cryptocurrency wallet information before transmitting it to remote servers.

AMOS has been active in cybercriminal circles for months, but this campaign marks a significant escalation in its distribution tactics through trusted platforms. How the Fake Codex Pages Evade Detection The fraudulent sites mimic OpenAI’s branding closely, using similar logos, layouts, and technical jargon to reduce user suspicion. Unlike typical phishing attempts, these pages avoid obvious spelling errors or poor design, making them harder to distinguish at a glance. Researchers noted that the malware payload is often bundled with a seemingly functional installer, which runs a decoy process while silently deploying AMOS in the background. This dual-action technique increases the likelihood of successful infection, as users believe they have installed the intended tool. Why Are macOS Users Being Targeted Now? Despite macOS’s reputation for stronger security, its growing popularity among developers and professionals has made it a more attractive target for cybercriminals.

The rise in AI-assisted coding tools has created a new vector for exploitation

The rise in AI-assisted coding tools has created a new vector for exploitation, as users frequently seek downloads for productivity enhancements. Attackers are leveraging this trust in AI brands to bypass traditional security awareness, knowing that users may lower their guard when seeking cutting-edge software. This trend reflects a broader shift in malware distribution toward exploiting demand for emerging technologies. Frequently Asked Questions How can users verify if a Codex download is legitimate? Users should only download OpenAI Codex from official OpenAI websites or verified developer portals, avoiding third-party links from ads or unfamiliar sites. Checking digital signatures and verifying URLs carefully can help prevent infection. What signs indicate a Mac might be infected with AMOS? Sudden password changes, unfamiliar login attempts, or unexplained network activity may suggest compromise. Running updated antivirus software and monitoring system processes can aid in early detection.

Is Apple planning to improve defenses against such impersonation schemes? Apple continues to enhance Gatekeeper and XProtect protections, but user vigilance remains critical. The company encourages reporting suspicious apps through its Feedback Assistant to help improve threat intelligence.

Read full article on Tech Site News →