started · updated
MacSync malware targets macOS users via fake Claude Code guides
Security researchers have identified a sophisticated malware campaign targeting macOS users through a fraudulent Claude Code installation guide. The attack, dubbed ‘MacSync’ by security firm Huntress, utilizes paid Google advertisements to direct users to a malicious step-by-step guide hosted on the legitimate claude.ai platform via Anthropic’s public chat-sharing feature.
Because the guide is hosted on the official domain, it carries Anthropic’s valid security certificates, preventing browser warnings. The attackers further deceive users by setting the chat display name to ‘Apple Support,’ a name that is subsequently validated by Anthropic’s own safety banner.
Once a user executes a command in the Terminal as instructed by the guide, the six-stage malware chain installs a stealer and a remote access Trojan. The final stage of the attack involves replacing legitimate cryptocurrency wallet applications, such as Ledger and Trezor, with Trojanized versions. These fake apps present a fraudulent recovery screen designed to harvest seed phrases, allowing attackers to drain the victim's digital assets.