A large cluster of lookalike download domains is being used to selectively serve macOS users infostealer payloads, with the lure hidden behind browser fingerprinting and ClickFix-style social engineering.
A malvertising campaign is using Google Ads and a fake Claude Code installer to reach macOS users, showing how cybercrime now leans on trust instead of obvious exploits.
A malvertising campaign dressed up as a Claude Code setup guide shows how one pasted command can turn a developer workstation into a map of reusable secrets.