Zscaler Details MacSync Campaign Using Claude Shared Chats Zscaler disclosed on July 15 that a June 12-19 malvertising campaign used Google Ads and legitimate Claude shared-chat pages to deliver MacSync Stealer to macOS users. The company observed 22 campaign IDs and said the malware targeted credentials, sensitive files, cloud configuration and cryptocurrency-wallet data; Anthropic had removed access to the reported chats by publication time. Zscaler Details MacSync Campaign Using Claude Shared Chats Zscaler disclosed on July 15 that a June 12-19 malvertising campaign used Google Ads and legitimate Claude shared-chat pages to deliver MacSync Stealer to macOS users. The company observed 22 campaign IDs and said the malware targeted credentials, sensitive files, cloud configuration and cryptocurrency-wallet data; Anthropic had removed access to the reported chats by publication time. Zscaler disclosed on July 15 that attackers had used paid Google search ads and legitimate Claude shared-chat pages to deliver MacSync Stealer to macOS users. Its Threat Hunting team observed the campaign from June 12 through June 19 and identified 22 campaign IDs across searches including “claude,” “claude code” and “claude mac.” The disclosure describes abuse of Claude’s sharing feature, not a vulnerability in Claude Code or a compromise of Anthropic’s infrastructure. Zscaler said it notified Anthropic, and the reported shared chats were no longer accessible when its research was published. How the campaign built trust A victim searching for Claude software could see a paid result that led to a real claude.ai shared-chat URL. The attackers made the chat appear to be “Shared by Apple Support,” which Zscaler said was likely achieved by setting the account display name to that phrase. The page instructed the victim to paste a Terminal command. That command used Base64 encoding to hide a download URL and piped the retrieved script into zsh. The technique is a form of ClickFix: the attacker persuades the user to run the harmful instruction instead of exploiting a software flaw. Independent reports from GBHackers and IT Brief described the same Zscaler findings. The trusted domain and familiar interface mattered because they reduced the warning signals a user might expect from a conventional fake-download site. What MacSync attempted to collect Zscaler documented a multi-stage chain. A second-stage shell script suppressed visible output, retrieved the core payload and attempted to upload collected data in 10 MB chunks. The malware could establish persistence through .zshrc when it lacked access to browser cookies and could show a fake prompt seeking Full Disk Access. The reported collection targets included macOS keychain files, Chromium and Firefox credential data, password-manager and cryptocurrency-wallet extensions, shell history, SSH keys, AWS and Kubernetes configuration, Telegram data, Apple Notes and selected documents. Zscaler also observed code that attempted to fetch additional payloads for Ledger Wallet, Ledger Live and Trezor Suite, but the researchers said those payloads were unavailable during analysis. That limitation means the campaign should not be described as having conclusively modified those applications in every infection. What defenders can verify The campaign’s practical lesson is narrow: a legitimate hosting domain does not make a copied shell command safe. Developer and security teams can reduce exposure by directing staff to vendor documentation, suppressing sponsored software-install results where appropriate and alerting on encoded curl commands, unexpected changes to .zshrc, temporary archives such as /tmp/osalogging.zip, and unusual outbound HTTP uploads. Anyone who executed a suspicious install command should isolate the device and rotate exposed browser, developer, cloud and wallet credentials from a clean system. The evidence supports treating the incident as a credential-theft campaign built on social engineering, not as proof that Claude Code itself was malicious. Key Points - 1Zscaler observed 22 Google Ads campaign IDs from June 12-19 that directed macOS users to malicious instructions hosted in legitimate Claude shared chats. - 2The MacSync chain used an obfuscated Terminal command and targeted browser credentials, keychains, SSH keys, cloud configuration, sensitive files and cryptocurrency-wallet data. - 3Zscaler notified Anthropic, and the reported shared chats were inaccessible when the July 15 research was published. Scoring Rationale The campaign abused paid search and a legitimate AI-sharing surface to reach developers and target high-value browser, cloud and wallet credentials. Zscaler supplied dates, campaign counts, technical behavior and indicators, while the article preserves the boundary that this was social engineering rather than a Claude Code vulnerability. Sources Primary source and supporting public references used for this report. Practice interview problems based on real data 1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with. Try 250 free problems /problems