Push Security documented a malvertising chain in which a Google search ad for "claude mac" listed bing.com as its domain and, three redirects later, delivered victims to a fake Claude download page. The firm says it caught the attack in a customer environment.
Push Security's researchers traced four requests behind the click. Google's ad-click redirect handed the browser to a Bing search-result link, which forwarded it with JavaScript to the "about us" page of a compromised homeopathy retailer in South America. That site then sent the visitor to claude-desk-code[.]com, a copy of Anthropic's download page. A timestamp inside the Bing link decodes to October 5, 2026, probably the moment Bing generated it. The firm found no earlier public reporting of a search ad that points at a search result, and says Google's ad review approved a destination that was simply another search engine.
Two separate checks keep the chain hidden from anyone not walking it the intended way. The compromised site answers only visitors who arrive with a Bing referrer and certain browser headers. The fake Claude page runs its own script, reads document.referrer and sends anything without Google or Bing in it to a 404 page, so typing the address directly shows nothing. Reaching the payload from Bing works too, which Push Security reads as an unintended side effect and as a sign that Google users are the real target. A scanner or ad reviewer that fetches the chain cold gets an error page, and that is the design.
The fake page offers a "Download for macOS" button and a one-line terminal install, the InstallFix variant of ClickFix in which victims paste an install command themselves. It displays Anthropic's real command, curl -fsSL https://claude.ai/install.sh | bash, but the Copy button puts a different one on the clipboard. That command prints a line naming the genuine Claude installer address, then decodes a hidden URL and pipes a script from lake-90[.]com into zsh. Someone who compares the page with the terminal output sees Anthropic's real address both times; only the clipboard contents differ.
Push Security tracks the toolkit behind the page as AcSig, after finding several domains that share an identical macOS command, the same payload URL shape and the same install modal code. It lists them among its indicators of compromise, though it cautions that such short-lived indicators carry limited weight against infrastructure that rotates within days. Search engines deliver four in five of the ClickFix attacks the firm detects, it says, and it expects more attackers to adopt a cheap extra hop like this one.













