A new digital scam is targeting Mac users , exploiting their trust in Google’s top searches . Specifically, attackers buy sponsored results to place fake Homebrew websites above the official page, tricking users into executing Terminal commands that install malware . The method is effective precisely because it relies on human behavior rather than exploit techniques.

Homebrew is a must-have tool for developers and everyday Mac users, as it allows them to install software with a simple Terminal command. This process makes the platform a particularly attractive target, as a fake command looks normal and does not raise suspicion. Attackers exploit users' expectation that installation requires copying and pasting commands, thereby adding a hidden payload that can steal sensitive data.
See also: Russian CTRL Toolkit: New malware steals passwords and data
Fake Homebrew Ads: How They Work
Attackers start with a sponsored Google listing that appears above the organic results of the official Homebrew website. The fake page mimics the legitimate one almost exactly, but replaces the installation command with a script that hides malware. According to reports on Reddit, the command is encoded in Base64, which hides the intent behind the innocent-looking text. Once pasted into Terminal, the command decodes and installs software information-stealing, known as AMOS or Atomic macOS Stealer, which targets browser data, credentials, and even cryptocurrency.
This technique is effective because it blends into the familiar Homebrew installation experience. Users are familiar with the copy-paste command, and Base64 encoding reduces the visibility of any suspicious activity. The result is an attack that leverages user behavior rather than technical exploits, a method known as “user-driven compromise.”
See also: Hackers impersonate CERT-UA to distribute RATs on government networks

Why is the attack so successful?
The human element is the Achilles heel of Mac users in this case. People trust that the first search result is legitimate, especially when it comes to a familiar tool like Homebrew. The combination of a fake page with familiar installation steps reduces suspicion just when the user is ready to execute the command.
Google sponsored results make things even more difficult, blurring the line between legitimate and paid links. Attackers can quickly switch domains, making it difficult to track and prevent them. Base64 encoding adds another layer of deception, allowing malicious commands to go undetected.
Practical instructions for your protection
The safest method is to go directly to the official Homebrew website . By bookmarking it or manually typing in the URL , users avoid falling for fake ads. Any Terminal command that looks vague or coded should immediately raise suspicion .
See also: Citrix NetScaler: Vulnerability used in reconnaissance activities

Additionally, using an ad blocker reduces the chances of sponsored results appearing before legitimate links. In case a suspicious command, users should take immediate action: change passwords, enable two-factor authentication , and check for persistence mechanisms used by malware to survive reboots.
The new form of attacks against Mac users shows that digital security is increasingly dependent on vigilance . As attackers shift their activity from technical exploits to human-driven breaches, awareness and attention to every step of the installation process becomes critical to the security of personal data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
