Fake Claude install guide deploys MacSync stealer
Attackers built a fake Claude Code installation guide hosted on Claude.ai's own chat-sharing pages to trick Mac users into pasting a command into Terminal. Running it installs MacSync, a stealer that grabs passwords, cloud and SSH keys, screen activity, and rewrites crypto wallet apps to phish the recovery phrase.
- Report priority
- Medium
- Targets
- Claude.ai+1 more
How it works
Victims click a paid Google ad for help installing Claude Code, land on a shared Claude.ai conversation styled as Apple Support instructions, and copy a curl command into Terminal that runs a small loader script which unpacks a hidden payload and starts a six-stage infection asking for Full Disk Access and Screen Recording.
What to do
If you pasted and ran a Terminal command from a sponsored Google ad or a shared Claude.ai conversation claiming to be an Apple installation guide, or if a wallet app on your Mac suddenly asked for your recovery phrase, check for unrecognized entries with the command below.
There is no software patch since this is a scam page rather than a Claude bug, so never run install commands from search ads or shared chat links, remove any LaunchAgent you do not recognize, revoke Full Disk Access or Screen Recording from unfamiliar apps in System Settings, and move funds to a brand-new wallet if you ever entered a recovery phrase into a wallet app that showed an odd error.
Technical details
Affected software: Claude.ai, macOS
Someone searches Google for how to install Claude on a Mac and clicks a sponsored ad instead of the real result. The ad leads to a Claude.ai conversation made to look like Apple Support instructions telling them to paste a command into Terminal. Running it quietly installs MacSync and asks for Full Disk Access, which lets it copy browser passwords, Keychain secrets, and Telegram sessions, then rewrite the person's crypto wallet apps so they later show a fake error page asking for the wallet recovery phrase.
MacSync arrives through a ClickFix-style zsh loader that decodes a Base64 payload and runs a six-stage chain, executing an AppleScript in memory and requesting Full Disk Access to harvest Keychain items, browser cookies, saved logins, Telegram sessions, and cloud or SSH keys. It installs a LaunchAgent-based remote-access trojan for persistent interactive shell access and file transfer, while a separate signed helper requests Screen Recording. In its final stage it detects dozens of wallet browser extensions and desktop apps, including hardware-wallet companion software, and replaces them with trojanized copies that show fake error dialogs to phish the seed phrase. Huntress traced the activity to a July incident response case.
References
- ppl-ai-file-upload.s3.amazonaws.com · Hackers-Use-Fake-Claude-Install-Guide-to-Deploy-MacSync-Stealer-and-Trojanize-Crypto-Wallet-Apps.pdf Cyber Security News
- huntress.com · fake-claude-macsync Cyber Security News
- any.run · threat-intelligence-feeds Cyber Security News
- thehackernews.com · threatsday-ghostjacking-ai-attacks.html TheHackerNews
- openwall.com · 14 Openwall oss-security
- thehackernews.com · windrelay-android-malware-turns-victims.html TheHackerNews
- thehackernews.com · silkparasite-espionage-campaign-targets.html TheHackerNews
- thehackernews.com · evooo1bot-linux-botnet-exploits-known.html TheHackerNews
- gbhackers.com · balonx-phaas-steals-bank-otps GBHackers