A sophisticated malvertising campaign dubbed “InstallFix” is actively leveraging Google Ads and, remarkably, legitimate Claude.ai shared chats to distribute the MacSync infostealer to macOS users and credential-stealing trojans to Windows users. The campaign was flagged by multiple security firms including Bitdefender, Trend Micro, and Rapid7 in mid-May 2026.

The attack is particularly insidious because the macOS infection chain is hosted on claude.ai itself. Threat actors create shared Claude chats disguised as official “Claude Code on Mac” installation guides — sometimes attributed to “Apple Support” — that instruct users to open Terminal and paste a malicious command. Because the instructions live on a legitimate Anthropic domain, there’s no suspicious URL for security-aware users to flag, and no certificate warnings are triggered.

The MacSync infostealer harvests browser saved credentials, cookies, macOS Keychain contents, and cryptocurrency wallet seed phrases, packaging everything as /tmp/osalogging.zip for exfiltration. It operates as a Malware-as-a-Service platform with polymorphic payloads — each request generates uniquely obfuscated code, making signature-based detection extremely difficult. Windows variants deliver credential-stealing trojans and in some cases PlugX remote access malware.

Source

Bitdefender Labs — Fake Claude Code Google Ads Malware | Trend Micro Research

Commentary

This campaign is a masterclass in social engineering that exploits the current AI gold rush. The clever part isn’t the malware itself — it’s the delivery mechanism. By hosting the attack instructions as a shared chat on Claude’s own domain, the attackers effectively weaponize the trust users place in legitimate platforms. It’s the same pattern we’ve seen with GitHub, Google Docs, and other trusted platforms being abused as malware hosting — but applied to the newest class of trusted AI tools.

If you’ve searched for “Claude installer” or “Claude Code” via Google recently and followed any non-official installation instructions, assume compromise and rotate credentials immediately. The only legitimate installation sources are docs.anthropic.com and claude.com/download.

By Allan