A legitimate domain was only the first hop

A Google ad that appeared to point to Bing was an unlikely route to a fake software installer. Push Security observed exactly that during a search for Claude on macOS. The sponsored result used Bing's search-result redirect, then sent the browser through a compromised retail website to a fake Claude download page.

The chain matters because each hop can look less suspicious than the destination. The Bing domain was real, and the intermediate retailer was a legitimate website that had been compromised. Push also found checks that changed what visitors saw depending on the referrer and browser context. Visiting the final address directly could produce a different result from following the ad as a user would.

The visible command was not the copied command

The fake page displayed Anthropic's legitimate-looking installation command. Its Copy button placed a different command on the clipboard—one that decoded another address, retrieved a script and piped it into the macOS shell. A person comparing the page with the vendor's instructions might believe the command was safe, then paste something else.

Do not invent a payload

Push traced the delivery chain and malicious command, but said the final payload remained unknown. There is not enough evidence here to call this a confirmed infostealer or to name a malware family.

Investigate the journey, not just the landing page

  1. 1

    Preserve the full navigation. Capture the ad click, redirect sequence, referrers and final destination where browser or proxy telemetry allows. A direct visit to the landing domain may miss cloaked behavior.

  2. 2

    Inspect the executed command. Compare what the page displayed with what the user pasted and ran. Look for encoded URLs and a shell fetching and executing remote content.

  3. 3

    Assess the endpoint. If the command ran, preserve terminal history and endpoint evidence, identify the fetched script and any subsequent process or network activity, and contain according to the findings.

  4. 4

    Reduce repeat exposure. Point staff to the vendor's documented download path and teach them to inspect the pasted command before execution, especially when an installer asks for a terminal command.

A trusted URL can still be a redirect

“Check the domain” is too narrow for this case. Trusted domains can carry redirect links, and the text next to a Copy button can differ from the clipboard. The useful evidence is the complete path from search result to executed command.