AI-poisoned downloads turn trusted tools into mac malware traps

Bleeping Computer

The gist

Cybercriminals are hijacking trusted AI and developer platforms to turn legitimate macOS tools into stealthy malware traps—poisoning downloads and even AI chat responses to weaponize your own workflow against you.

What to know

  • Attackers are abusing Google Sites, Google Ads, and Claude.ai to deliver AMOS infostealer via malicious Terminal commands and AI-generated links disguised as trusted developer tools.
  • AI chatbots like Claude are being manipulated to embed poisoned download links and sneaky reinfection commands directly in their responses and config files, tricking even savvy devs.
  • Obfuscated payloads, multi-stage redirects, and npm/PyPI malvertising are turning standard developer workflows into persistent macOS infection vectors—highlighting the urgent need for zero-trust on all AI-suggested links and scripts.

Google’s Infrastructure as a Weapon

Attackers are hijacking Google’s trusted platforms and AI assistants to deliver stealthy Mac malware, using layered obfuscation and persistent infection tactics that weaponize user trust as the primary payload.

Attackers have ingeniously exploited trusted platforms such as Google Sites and Google Ads to craft and promote fake AI developer tool download pages, notably impersonating OpenAI’s Codex. By leveraging stolen Google Ads accounts and embedding malicious content via iFrames rather than hosting malware directly, they maintain a veneer of legitimacy that exploits users’ inherent trust in Google’s infrastructure. This tactic not only helps bypass detection by security systems but also deceives macOS users into executing Terminal commands that install the AMOS infostealer, cleverly mimicking authentic AI tool installation processes.

The campaign’s sophistication extends beyond Google’s ecosystem, infiltrating AI platforms like Claude.ai by embedding poisoned download links and hidden malicious instructions within AI-generated responses and configuration files. This novel vector exploits users’ trust in conversational AI assistants as reliable sources, leading them to unwittingly execute harmful Terminal commands. The attackers’ use of subtle system prompts within configuration files to silently redownload malware upon new coding sessions exemplifies a persistent infection strategy that evades traditional detection methods.

To further complicate detection and analysis, the attackers employ multiple evolving infrastructure sets with advanced obfuscation techniques such as AES-encrypted gzip containers and variable-based decryption keys. This layered approach ensures that no single stage of the attack—whether search delivery, embedded content, Terminal execution, or outbound telemetry—fully reveals the campaign’s scope, effectively weaponizing user trust in legitimate platforms as the primary vector for infection. As noted in security analyses, this multifaceted exploitation of Google’s and AI platforms’ trusted environments turns 'trust into the payload,' making mitigation a formidable challenge.

Sources

AI-Personalized Social Engineering

AI-generated messages and chatbots now tailor phishing and malware delivery with convincing, hyper-personalized content, making even experienced users vulnerable to malicious links and hidden reinfection scripts.

AI-driven social engineering scams have evolved to exploit users’ egos by generating hyper-personalized, flattering messages that make individuals feel uniquely recognized and valued, thereby lowering their guard. By rapidly scraping publicly available data, AI can craft convincing biographies and tailored invitations in seconds, mimicking the effort of a human and making malicious communications appear genuinely personal. However, this surge in AI-generated personalization means users can no longer trust messages simply because they contain detailed personal information, as attackers can fabricate seemingly sincere interactions at scale.

Threat actors are now weaponizing AI chat sessions, such as those on Claude.ai, by poisoning AI-generated outputs to embed malicious download links and pre-formatted terminal commands that users are psychologically primed to trust. In one documented case, a startup founder was compromised after executing a software installation command directly provided within a Claude chat, illustrating how attackers manipulate user confidence in AI assistants as reliable sources. This trust is further exploited through hidden malware reinfection mechanisms embedded in innocuous-looking configuration files, which silently instruct the AI to redownload malware during routine developer workflows.

This emerging attack vector marks a fundamental shift from traditional phishing and SEO poisoning toward sophisticated manipulation of large language model responses, demanding a zero-trust approach to AI-generated content. Microsoft Defender experts highlight that every external link and shell script recommended by AI must undergo rigorous manual verification, as the automatic acceptance of AI outputs can lead to widespread infections. As AI becomes embedded in developer tools and workflows, technical professionals must adapt by treating conversational AI outputs with the same suspicion as unverified external inputs.

Sources

npm Supply Chain: Mac’s Weak Link

Malicious npm packages and mirrors bypass Apple’s security, silently stealing credentials and propagating malware at scale, with attackers exploiting trusted dependencies as a default vector for Mac compromise.

Attackers have innovated beyond traditional npm supply chain compromises by exploiting npm mirrors such as UNPKG to host malicious HTML phishing redirect pages directly from trusted domains. This tactic leverages the npm ecosystem as a free, validated web hosting platform, enabling phishing campaigns that bypass macOS security tools reliant on domain reputation. Furthermore, by using remote configuration services like api.keyval.org to dynamically update redirect URLs without republishing packages, adversaries enhance the stealth and persistence of their attacks.

Malicious npm packages pose an escalating threat to macOS users by circumventing Apple's Gatekeeper and notarization processes, as these packages execute code immediately upon installation without triggering any security prompts. This is particularly dangerous because developer Macs often store sensitive credentials, iMessage histories, Safari cookies, and cryptocurrency wallets alongside production keys. As a result, a single poisoned package with a post-install script can silently compromise critical assets, making the npm supply chain a prime vector for macOS malware.

The scale and sophistication of npm-based macOS supply chain attacks have surged dramatically, with Sonatype detecting over 454,600 new malicious packages in 2025 alone—99.8% originating from npm. Notably, there has been a marked shift toward data theft, with malware targeting tokens, keys, credentials, and wallets rising from 26% to 56% within a single quarter. This alarming trend is compounded by the widespread use of transitive dependencies, which invisibly propagate malicious code across multiple projects, effectively making supply chain compromise a default access strategy on macOS.

Recent high-profile macOS supply chain attacks between 2024 and 2026, including breaches involving Solana, the Nx 's1ngularity' incident, the 2.6-billion-download chalk/debug phishing campaign, the Shai-Hulud worm, and North Korean keychain-targeting operations, illustrate a persistent pattern of npm dependency poisoning leading to credential and wallet theft. Crucially, these attacks do not only affect developers; everyday macOS users are also at risk when trusted applications ship with compromised dependencies, resulting in stolen funds and breached personal data even among non-coding users.

Sources
The Good Tech CompaniesBleeping Computer

Weaponized AI Files & Malvertising

Attackers automate malware delivery by exploiting AI-readable files and advanced malvertising infrastructure, leveraging multi-stage redirects and dynamic cloaking to evade detection and maximize impact in lucrative markets.

Attackers have innovatively weaponized AI agent-readable llms.txt files by exploiting unclaimed package names and expired domains referenced in official vendor documentation, enabling autonomous delivery of malicious packages without any direct phishing or attacker interaction. This novel vector allows AI agents to treat these artifacts as authoritative instructions, autonomously discovering and executing attacker-controlled code within trusted developer workflows, effectively bypassing traditional endpoint detection mechanisms.

Malvertising campaigns have evolved from merely deploying deceptive content to weaponizing infrastructure through complex multi-stage redirect chains, cloaking, and dynamic behavior tailored to user signals such as geography or device type. By fingerprinting visitors and selectively delivering convincing impersonations only to targeted users while showing benign content to researchers or bots, attackers maintain persistence and evade detection, as evidenced by cloaking accounting for over 67% of advertiser suspensions in Q2 2026.

Economic incentives in lucrative Tier-1 markets like the US and UK drive attackers to invest heavily in sophisticated evasion infrastructure, including extended redirect chains and multi-domain setups, to maximize malware delivery success and maintain persistence. Higher cost-per-click and cost-per-acquisition values in these regions justify the complexity of these weaponized infrastructures, underscoring a strategic shift where malvertising functions as a dynamic, autonomous malware delivery system rather than simple deceptive advertising.

The convergence of AI agent exploitation and advanced malvertising tactics creates a formidable delivery ecosystem where trusted platforms and standard developer tools become unwitting accomplices in autonomous malware deployment. By leveraging legitimate package managers like PyPI and npm within approved AI coding tools, attackers embed malicious payloads deep into standard workflows, resulting in execution chains that resemble normal developer behavior and evade endpoint telemetry before any malicious activity is detected.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.