AI Briefing
KO

Beware of Google Ads Impersonating OpenAI Codex

·2026.08.17 19:42

Key point

Malware impersonating OpenAI Codex is being distributed via Google search ads to steal developer information.

1 / 2

Details

Cases have been reported of malware impersonating OpenAI Codex being distributed through Sponsored ads in Google search results.

Attack Mechanism:

  • Impersonation Page: Clicking the ad redirects users to a fake Codex installation guide page hosted on Google Pages.
  • Malicious Command Execution: When users execute the instructed command, it decodes a Base64-encoded URL to download a script from a specific server (quill-flint[.]com) and immediately executes it in zsh.
  • Obfuscation Techniques: Parts of the command are designed to look like a normal npm installation process to deceive users.

Risk and Impact:

  • Data Theft: Suspected to be an Infostealer malware capable of stealing browser (Chrome) passwords and cookies, Keychain data, SSH keys, and API tokens.
  • No Traces Left: The malware can terminate without leaving traces on the system after execution, posing a high risk of data exfiltration even if it does not leave a persistent payload.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.