Last updated: October 10, 2026
The quick answer
Security researchers at Push Security found sponsored Google results for “claude mac” that sent people to a convincing fake Claude download page, where the copy button for the install command secretly swapped in a malicious one. To stay safe, skip search ads when downloading software, type the official address yourself, and never paste a Terminal command you haven’t checked.
What happened
On October 9, 2026, Push Security published research on a malvertising campaign it nicknamed “Adception,” and BleepingComputer reported on it the same day. The attack chain went like this:
- A person searched Google for “claude mac” and saw a sponsored result showing bing.com as its address, which looks harmless.
- Clicking it passed through Google’s and Bing’s own click-tracking links, then landed on a hacked page belonging to a small retailer in South America.
- That page quietly forwarded the visitor to a lookalike Claude download site.
- The fake site displayed Anthropic’s real one-line Terminal install command, but its Copy button put a different command on the clipboard. That hidden command printed a legitimate-looking claude.ai address while downloading and running a script from an unrelated server.
The attackers also hid from security researchers: the hacked site and the fake page checked where visitors came from and showed a blank error page to anyone who didn’t arrive through a search ad. The researchers did not identify what the final script installs, and they linked the domains to a known kit used for “ClickFix” attacks, a growing scam style that tricks people into running commands themselves.
What changes for you
The big lesson is that what you see on screen isn’t always what you copy. Many AI tools, including developer tools, now install with a single command pasted into Terminal. That convenience is exactly what this scam abuses: the command on the page looked correct, and even the output in Terminal looked like it came from Claude’s real site.
The second lesson is that the address shown on a search ad isn’t proof of where you’ll end up. In this case, the ad showed a well-known domain and used real redirect services, so it passed a quick glance.
How to install AI apps safely
- Skip sponsored results for downloads. Scroll past ads and go to the vendor’s site directly. For Claude, type claude.ai or claude.com into the address bar, or use a bookmark.
- Prefer app stores and official installers. Where an app is offered through the Mac App Store or a signed installer from the official site, that’s usually safer than a pasted command.
- Paste into a text editor first. If you must use a Terminal command, paste it into Notes or TextEdit and read it before running it. Be wary of anything containing long scrambled strings, “base64,” or a web address that doesn’t match the vendor’s official domain.
- Compare with official documentation. Check the vendor’s own help pages for the exact install command and make sure what you paste matches it character for character.
- Report suspicious ads. Google lets you report an ad from the menu next to it, which helps get malicious campaigns taken down.
If you think you ran the fake command
- Disconnect the Mac from the internet.
- Run a scan with reputable Mac security software.
- Check System Settings > General > Login Items for anything you don’t recognize.
- From a different, trusted device, change passwords for email, banking and any accounts saved in your browser, and turn on two-factor authentication.
- If it’s a work computer, tell your IT or security team right away.
Who it affects and who it doesn’t
This campaign targeted Mac users searching Google for Claude. If you downloaded Claude from the official site using an address you typed or bookmarked yourself, this specific scam doesn’t affect you. Using Claude in a browser at claude.ai, or through official add-ons like the one in our guide to Claude in Google Docs, Sheets and Slides, isn’t affected either.
The technique isn’t limited to Claude, though. Any popular app with a command-line installer can be imitated the same way, so the habits above apply broadly. For more on how macOS is changing to limit what AI tools can access, see Apple tightening Full Disk Access because of AI agents. Also today: malware found preinstalled on budget Android phones.
FAQ
Was Anthropic or Claude hacked?
No. Nothing in the reports suggests Anthropic’s systems were compromised. The attackers built a fake page that imitated Claude’s real download instructions.
What does the malicious command install?
The researchers didn’t confirm the final payload. Commands like this can install anything the attacker chooses, which is why running unknown Terminal commands is risky.
Can an ad blocker help?
It can reduce exposure to sponsored results, but the most reliable defense is going straight to the official site and checking any command before you run it.



Leave a Reply