Mac users seeking assistance with installing Claude Code are being targeted by a sophisticated malware campaign that transforms a routine setup into a full-scale device compromise. This operation leverages paid Google search results and a deceptive shared Claude conversation to convince users to execute a command in Terminal, leading to the installation of MacSync, an information-stealing malware.
The attack initiates when a user searches for terms like “how to install Claude on a Mac” and clicks on a sponsored link. Instead of accessing official documentation, the user is redirected to a Claude conversation page designed to appear as if it originates from Apple Support. This misuse of trusted services mirrors previous instances where shared Claude chats were exploited in similar ClickFix attacks.
The fraudulent page instructs visitors to copy and paste a curl command into Terminal. This command downloads MacSync, a stealer malware engineered to collect credentials, private data, and cryptocurrency wallet recovery phrases. The command employs Base64 encoding to obscure its true destination, which, when decoded, fetches the malicious payload from an attacker-controlled server.
Once executed, MacSync requests extensive macOS permissions, including Full Disk Access. If granted, it can harvest browser cookies, saved logins, Keychain secrets, account passwords, Telegram sessions, and cloud credentials. Additionally, MacSync establishes persistence through a LaunchAgent, enabling attackers to maintain access even after system reboots.
In a particularly alarming development, MacSync targets cryptocurrency wallet applications. It identifies installed wallet software and replaces it with trojanized versions. These compromised applications can display fake error messages prompting users to enter their recovery phrases. Unlike passwords, exposure of a recovery phrase grants full control over the associated cryptocurrency wallets, posing a significant financial risk.
Security researchers emphasize the importance of vigilance when executing commands in Terminal. Users are advised to download software exclusively from official vendor websites, scrutinize unfamiliar commands before execution, and deny unexpected permission requests. This incident underscores the evolving tactics of cybercriminals who exploit trusted platforms and user habits to deploy malware.
As cyber threats become increasingly sophisticated, it’s crucial for users to exercise caution and verify the authenticity of installation guides and commands. This case highlights the need for heightened awareness and proactive security measures to protect against such deceptive attacks.