Summary
Cybercriminals are using fake OpenAI Codex download pages hosted on Google Sites and promoted via stolen Google Ads accounts to infect macOS users with the AMOS infostealer malware. The campaign tricks users into pasting Terminal commands, exploiting Google's trust signals to appear legitimate.