Mac customers looking for assist with Claude Code are being lured right into a malware marketing campaign that turns a routine set up job right into a full gadget compromise.
The operation makes use of paid Google search outcomes and a convincing shared Claude dialog to steer victims to run a command in Terminal. The marketing campaign places on a regular basis Mac customers at severe threat.
The page is hosted on Claude.ai, which gives the lure an air of legitimacy, but it is not an official installation guide.
It tells visitors to copy and paste a curl command that downloads MacSync, an information stealer built to collect credentials, private data and cryptocurrency wallet recovery phrases.
Huntress analysts identified the activity after responding to an incident involving a customer who clicked the sponsored result in July.
Their investigation found a complete attack chain combining in-memory theft, persistent access and altered wallet apps.
.webp)
Huntress said in a report shared with Cyber Safety Information (CSN) that blend makes a single rushed Terminal command pricey for people and organizations.
Hackers Use Fake Claude Install Guide
The attack starts when someone searches Google for terms such as how to install Claude on a Mac and selects a sponsored listing.
Instead of reaching official documentation, the person lands on a Claude conversation styled as if it came from Apple Support. This misuse of trusted services mirrors earlier shared Claude chat abuse reported in related ClickFix exercise.
The false instructions rely on ClickFix, a social engineering method that gets victims to run the attacker’s command themselves.
In this case, the command launches a small zsh loader, which unpacks an encoded payload and begins the six-stage chain with little visible warning.
.webp)
The researchers said the loader changes for each victim, making simple file-hash blocking unreliable. Defenders should instead watch for unusual curl activity, encoded Base64 content in shell commands and unexpected Terminal downloads.
MacSync then runs an AppleScript directly in memory and asks for powerful macOS permissions, including Full Disk Access.
If the user approves, it can harvest browser cookies, saved logins, Keychain secrets, account passwords, Telegram sessions and cloud credentials. Related macOS ClickFix attack tactics present why permission prompts deserve cautious scrutiny.
The stealer also plants a remote-access trojan that survives future logins through a LaunchAgent. This gives operators an interactive shell, the ability to run commands and transfer files.
A separate signed helper seeks Screen Recording permission, allowing the attackers to capture the victim’s display after consent is granted.
Wallet Trojans Raise Stakes
The final stage targets applications users already trust. MacSync checks for dozens of wallet browser extensions and desktop wallet programs, then copies and rewrites selected apps.
It also targets companion applications for hardware wallets, turning familiar software into a phishing tool.
When a victim later opens a modified wallet app, it can display a fake error page requesting the recovery phrase.
Unlike a password, a wallet recovery phrase cannot simply be reset after exposure. Anyone who obtains it may control every wallet created from that seed, a danger also seen in wallet replacement malware risks.
Users should never paste a command into Terminal solely because a search ad, chat page or support-looking post tells you to do so.
Download software from the vendor’s official site, inspect unfamiliar commands before running them, and deny unexpected permission requests.
.webp)
Security teams should review alerting for shell-based download chains, as recent ClickFix campaign coverage exhibits the tactic stays extensively reused.
For users who may have executed the lure, promptly disconnecting the Mac from networks, changing exposed passwords from a clean device and moving cryptocurrency assets to a new wallet can limit further loss.
Organizations should also investigate browser sessions, cloud access tokens and persistence entries, since removing the visible installer alone may not remove the attacker’s access.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP address and port | 85.206.161.241:8443 |
Direct command-and-control endpoint used by the Mach-O RAT through WebSocket over TLS |
| File path | /tmp/osalogging.zip |
Archive used to stage and exfiltrate stolen data |
| File name | .mpwd |
Local file where stolen user credentials are written for RAT retrieval |
| File name | .zshrc |
Resource file used to launch persistence mechanisms |
| Function name | daemon_function |
Background zsh function that runs the AppleScript payload, uploads stolen data and removes staging material |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world