Fake Claude installer spread via Google ads that showed bing.com — the Copy button swaps the command
A "claude mac" Google ad led Mac users through Bing and a hacked site to a fake Claude page whose Copy button pasted a malicious install command.
A Google search ad for "claude mac" sent people through a chain of legitimate-looking redirects to a fake Claude download page, where the "Copy" button swapped Anthropic's real install command for a malicious one. Push Security published the campaign on October 9, 2026; it targets macOS users installing Claude Code. Install AI command-line tools only from the vendor's own documentation or a package manager, and never run a terminal command copied from a page you reached through an ad.
What happened, in plain English
Many AI coding tools, Claude Code included, are installed by pasting one line into a terminal. That line downloads a script from the vendor and runs it straight away. It is convenient, and it also means the person pasting the command is trusting the web page completely.
On October 9, 2026, the browser-security company Push Security described a campaign that abuses that trust. Someone searching Google for "claude mac" saw a sponsored result (an ad) that displayed bing.com as its address. Clicking it went through Google's ad redirect, then through a Bing click-tracking link, then through a hacked website belonging to a South American retailer, and finally landed on claude-desk-code[.]com, a convincing copy of a Claude download page.
The page showed Anthropic's genuine install command. But the "Copy" button put a different command on the clipboard. When pasted into Terminal, it printed a reassuring message about downloading Claude from the official site, then quietly fetched a script from a different server, lake-90[.]com, and ran it.
Think of it as a shop that shows you the real product in the window and hands you a different box at the counter. Everything you looked at was genuine; the thing you took home was not.
Push calls the redirect trick "Adception". It is one variant of a technique the company named InstallFix in March 2026: cloning a real tool's install page and swapping the command. "ClickFix" is the wider family of attacks that persuade people to paste and run commands themselves.
Push has not said what the final script installs, and it detected the attack in one customer environment. There is no victim count.
Are you affected? What to do now
Who should care: anyone who has installed Claude Code (or another AI command-line tool) on a Mac by following a search result, and IT teams whose developers install their own tools. The documented chain targets macOS; Push did not describe a Windows variant of this specific campaign, although earlier InstallFix pages had Windows commands too.
Check exposure
- Ask staff who installed Claude Code recently where they got the command. The official sources are Anthropic's setup documentation or a package manager. An ad or an unfamiliar domain is a red flag.
- Search proxy, DNS and web-filter logs for the domains Push published (defanged):
claude-desk-code[.]com,cli-desktop[.]com,ksmgakajgpsals.pages[.]dev,rapid-craft567[.]com,too.clawddddd[.]com,fine-byte2[.]com,fairpoint29[.]com,turbowave45[.]com, the redirect pagehomeopatiaalemana[.]com/quienes-somos/and the payload hostlake-90[.]com. Push warns that these addresses rotate quickly, so a clean result is not proof of safety. - On managed Macs, look in endpoint (EDR) telemetry for a
curldownload piped directly intozshorbashfrom a domain other thanclaude.ai, especially right after a browser session.
If someone ran the command
- Treat the Mac as compromised: isolate it and follow your incident process. Because the payload is unknown, assume it could steal saved passwords and browser sessions. Push linked earlier InstallFix pages to the Amatera infostealer, which targets exactly those.
- Reset passwords used on that machine, sign out all active sessions (email, SSO, GitHub, cloud consoles) and rotate API keys and tokens stored there, including AI-provider keys.
Prevent the next one
- Install Claude Code from the documented sources: the native installer on
claude.ai, Homebrew (brew install --cask claude-code), WinGet, or Anthropic's signed apt, dnf and apk repositories. Anthropic's documentation also explains how to verify the signed release manifest and the macOS code signature. - For company devices, push AI tools through your software-deployment tool or an approved package source instead of leaving developers to search for installers.
- Awareness point for everyone: ads can show a trusted address and still lead somewhere else. Type the vendor's address yourself or use a bookmark.
- After pasting any install command, read what actually landed in the terminal before pressing Enter. If it contains encoded text or a domain you did not expect, stop.
If nobody in your organisation installs command-line AI tools on Macs, there is nothing urgent to do beyond the awareness point.
The expert view
Nothing here is technically new in isolation. Malvertising, open redirects and paste-and-run social engineering are all old. What is worth noting is how the pieces are put together, and why AI developer tools make good bait.
The redirect chain is built to defeat checks, not people. Google shows the domain of an ad's destination. Pointing the ad at a Bing click-tracking URL, which forwards with JavaScript rather than a server redirect, means the displayed domain is a reputable one. The browser also reaches the next hop with a Bing referrer. The compromised retailer site checks for that referrer and certain browser headers. The fake Claude page then checks again in the browser and sends anyone not arriving from Google or Bing to a 404 page. Ad reviewers, URL scanners and researchers who visit directly see nothing. Push says the payload "only appeared if you reached the end of the chain through this specific path." Two legitimate platforms and one innocent victim site are used as cover.
The copy-button swap removes the last visual check. The page shows the real command, the terminal echoes a real claude.ai URL, and the actual download location is base64-encoded so it does not stand out. The victim runs the code themselves, in their own user context, so typical defences against malicious downloads, such as file-reputation checks, do not get a chance to look at a file first.
Why AI tools? Install-by-curl | bash is the normal, documented method for many AI agents and CLIs, so users are already used to the behaviour the attacker needs. The people installing them are often developers whose machines hold source code, cloud credentials, SSH keys and AI API keys. Those are valuable for resale and for follow-on intrusions. Push says four in five of the ClickFix attacks it detects, including InstallFix variants, now reach victims through search engines rather than email.
What fits the broader trend: this site has covered lookalike domains around AI brands before, including the 167 "Jev AI" domains. AI tools are a strong brand to impersonate because demand is high, many users are new to them, and the official install methods vary.
Detection takeaways, conceptually: blocking indicators has limited value against rotating infrastructure, as Push notes. More durable signals are behavioural: a shell process fetching and immediately executing remote content shortly after a browser session, clipboard contents that differ from what the page displayed, and installs of developer tools that do not come from managed channels.
Still unknown: what the second-stage script delivers, how long the ad ran, how many people clicked, and whether Windows users were targeted in this specific campaign. No source attributes the campaign to a named threat actor. Push tracks the related page kit internally as "AcSig" but has not published more about who runs it.
Official sources
- Push Security — "Adception": malvertising via another search engine's search results (October 9, 2026)
- Push Security — InstallFix: not the application you were looking for (March 6, 2026)
- Anthropic — Claude Code setup and installation documentation, including release verification
- Coverage: BleepingComputer — Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks (October 9, 2026)