Friday, 9 October 2026

Fake Claude download pages hide malware behind a Terminal command

Security researchers warn of an Adception tactic that uses legitimate Bing redirects and Google ads to deliver a fake Claude installer and potentially harmful payloads.

Close-up of a Mac computer screen showing a terminal window

The short version

  • Hackers abuse legitimate ad systems by using Bing redirects in Google search ads to push fake Claude installers.
  • The attack uses multi-layer cloaking and a compromised WordPress site to hide the payload from scanners.
  • Victims are led to a fake Claude download page that instructs a Terminal command, which actually runs a malicious script.
  • The final payload is unknown at this time, but the method makes it hard to tell what is installed.
Quick read · 2 min

Hackers have found a way to weaponize ads. They use Google search ads that redirect through Bing to a compromised site, landing on a fake Claude installer page. The page prompts a Mac user to run a Terminal command, which secretly downloads and executes malicious code. Researchers say the technique, called Adception, hides its payload behind legitimate ad pathways.

For everyday users, this means ads can lead to dangerous downloads even from trusted names. Protect yourself by verifying software sources, not running unfamiliar Terminal commands, and keeping your Mac’s security features enabled. If you think you were exposed, check your Terminal history and remove anything suspicious. The exact payload of these attacks isn’t public yet, but the method itself is enough reason to pause and verify before you install anything from an ad.

  • Verify sources on official sites
  • Avoid pasting unknown commands into Terminal
  • Update macOS and security tools regularly

Hackers are exploiting online ads to push a fake Claude installer, using a technique security researchers call Adception. The method blends legitimate advertising routes with covert redirects to deliver a malicious download page, then tries to run commands on the victim’s Mac. The campaign was spotted after researchers saw a Google search ad targeting people looking for Claude on a Mac, which then steered users through Bing’s redirect system to a compromised site before landing on a fraudulent Claude download page.

Why this matters to everyday users is simple: it can look like a normal ad from a trusted search result, and the final steps try to trick you into running commands in Terminal. The attackers cloak the process in two layers to dodge automated scanners, and they redirect visitors who arrive directly at the link to a 404 page to avoid detection.

So far, what’s inside the final payload isn’t fully revealed. The fake Claude installer presents what looks like Anthropic’s official install prompt, but the copy-and-paste command you’d typically run is replaced by a malicious instruction that downloads a hidden file and pipes it into the shell. In short, even careful Mac users could be fooled if they click the installer and run the shown command in Terminal.

Push Security, the security firm that named the attack vector, says it identified several domains associated with the same ClickFix toolkit, using a consistent pattern across the final payloads. The researchers warn that this approach makes it harder for scanners to distinguish between legitimate ads and exploit-laden pages.

01

How the Adception technique works

The attack starts with a Google ad tied to the term Claude on macOS. When you click, you’re first routed through Google’s ad redirect system, then sent to Bing’s click-tracking endpoint. From there, you’re forwarded to a compromised WordPress site that belongs to a South American retailer. The site then redirects you to a fake Claude download page hosted on claude-desk-code[.]com.

On the Claude page, you’ll see what looks like a legitimate installation command. If you click the copy button, the command appears copied to your clipboard. The hidden part of the attack executes a curl command that secretly downloads a data file and pipes it into the macOS shell. The attacker’s goal is to run code on your device without you realizing what’s happening.

Screenshot-like image showing search results and ads on a page
02

Who’s at risk

The campaign targets Mac users who search for Claude, and the final page surfaces a macOS installer prompt. Because the path includes legitimate ad networks and a compromised site, it can slip past some defenses that treat advertising channels as safe. It’s a reminder that ad networks can be abused to deliver malware alongside legitimate software recommendations.

03

What this means for you and your privacy

First, don’t click on suspicious ads even if they reference well-known software. If you’re unsure a download is legitimate, verify the source directly on the official site rather than following an ad link or a prompt in Terminal. On macOS, avoid pasting commands you can’t verify into Terminal, especially ones that download software or run complex scripts from the web.

Second, keep your software up to date and enable strong security protections. Modern Macs include built-in safeguards like Gatekeeper, but attackers are increasingly testing the edges of trusted networks, legitimate domains and ad routes to slip past them. A reputable ad‑blocker or security tool that can scan downloads before you run them is a good extra layer.

Graphic of a cybersecurity shield over a web traffic flow
04

What to do now

If you think you might have been exposed, there are practical steps you can take. Start by checking your Terminal history for unfamiliar commands and remove any suspicious files or scripts. Review installed apps and remove anything you did not install yourself. Consider resetting any compromised credentials and enabling two-factor authentication on critical accounts. If you’re unsure, reach out to Apple Support or a trusted cybersecurity resource for guidance.

05

Quick answers

What happened exactly?

Hackers used Google Ads and Bing redirects to send Mac users to a fake Claude installer page that runs a malicious command.

How can I protect myself?

Don’t run unfamiliar Terminal commands, verify software sources directly on official sites, and keep macOS security features enabled. Consider security software that scans downloads.

What should I do if I clicked one of these links?

Check Terminal history for the suspicious command, remove unknown files, and review installed applications. Change passwords if you entered credentials anywhere during the session.

You're reading the quick version.