Fake Claude Ads Route Through a Hacked Retailer’s Site

Affiliate disclosure: This post contains affiliate links. If you buy through them, I may earn a commission at no extra cost to you. Full disclosure

Push Security reported Oct. 9 that a Google ad for “claude mac” routed through Bing and a hacked retailer’s website to a fake Claude installer.

If you run a high-ticket store, you or your team installs a tool from a search result every few weeks, and one pasted command can hand an attacker your Shopify admin, your ad accounts and your bank logins. The ad in this attack displayed a bing.com address, so the filters and the instincts you rely on both passed it. That makes it a store-security story for Ecommerce Paradise readers, not a developer story.

Below is how the chain worked, why fake installer campaigns keep coming back, what it means for a store that runs ads and gives staff admin access, and six changes to make before Monday. I covered the Ninja Forms flaw that plants hidden WordPress admins yesterday, and this is the same family of risk: an attacker walking through a door you already trust.

Attackers hide behind domains you trust. Your business should hide behind a registered agent, so form your LLC with Northwest Registered Agent, the best LLC formation service for ecommerce owners. Northwest does not sell your address and puts its own address on your public filings, so your home address stays out of the public record. Form your LLC with Northwest →

Fake Claude Ad Used Bing and a Hacked Retailer as Cover

According to Push Security’s Oct. 9 research, written by Luke Jennings, the company spotted a Google search ad for the query “claude mac” inside a customer environment. The ad’s displayed domain was bing.com. Push nicknamed the technique “Adception,” a name its authors call unserious.

Push documented four hops. The click went to Google’s ad redirect, then to a Bing click-tracking link, then to the “about us” page of a compromised retailer, then to claude-desk-code[.]com, a fake Claude download page. Push says the Bing link encodes its destination in base64 and that its timestamp decodes to Oct. 5, which means the link existed four days before Push published.

The fake page does the damage. According to Push, it shows Anthropic’s real install command on screen, but the Copy button puts a different command on your clipboard. That command decodes a hidden address, pulls a script from lake-90[.]com and pipes it into zsh, the default macOS shell. After you paste it, the terminal prints a legitimate-looking Claude URL so nothing seems wrong.

Two layers of cloaking keep researchers out. Push says the compromised retailer’s page only forwards visitors who arrive with a Bing referrer and certain browser headers, and the fake Claude page sends anyone without a Google or Bing referrer to a 404. Type the address directly and you see an error page. Click the ad and you see the lure.

Push links the domains to a ClickFix toolkit it tracks as “AcSig,” based on HMAC-signed headers the pages require. It put two numbers on the delivery method: “4 in 5” of the ClickFix attacks it detects, including InstallFix variants, reach victims through search engines, and the header of its site claims “half of attacks now reach victims outside of email.”

Several things are not known. Push gave no victim counts, geographies or sectors. BleepingComputer, which covered the same campaign on Oct. 9, said the final payload is unknown, so the full impact is unclear. BleepingComputer describes the middle hop as a compromised WordPress site belonging to a South American retailer, and Push calls it a homeopathy retailer’s page. Neither names the retailer or explains how its site was compromised.

Fake Claude Installers Have Been Running Since March

Oct. 9 is not the first wave. On March 9, Dark Reading’s Rob Wright reported on “InstallFix”, Push’s name for cloned Claude Code install pages promoted through Google sponsored links. Victims who ran the copied command got the Amatera Stealer, which Dark Reading says can take developer credentials and open a path into corporate development environments.

That campaign triggered on three search terms: “Claude Code,” “Claude Code install” and “Claude Code CLI.” The attackers hosted pages on Cloudflare Pages, Tencent EdgeOne and Squarespace, three legitimate providers. Jacques Louw, Push’s co-founder and chief product officer, told Dark Reading that pasting a command from a site means “you’re effectively handing a website a blank cheque to execute whatever it wants on your system.”

Then Trend Micro published research on June 25 covering April 8 to June 14. It counted six attack waves in about seven weeks and at least six impersonated brands, including ChatGPT Codex, Perplexity, Cursor IDE, JetBrains and Claude. Of the campaign’s traffic, 82.8% targeted people searching for AI developer tools. Early waves used 92 unique hostnames on GitLab Pages, and from May 6 the attackers moved to claude.ai’s own shared-chat feature, which let fake “Apple Support” instructions sit on a trusted domain with a valid certificate.

Trend Micro says it notified Anthropic. Anthropic banned the accounts involved, disabled the malicious shared conversations and is rolling out additional abuse controls for shared chats.

The new piece on Oct. 9 is the laundering. Earlier waves bought ads that pointed at attacker pages. This one buys an ad that points at Bing, which points at a real shop’s site, which points at the lure, so the only domain a reviewer sees on the ad is Bing’s. Push argues that short-lived indicators of compromise have limited value because attackers rotate domains quickly, and it recommends analyzing the full browser session from the first click. Push is a security vendor, so that recommendation is also its product pitch. The advice to stop pasting commands from web pages does not depend on buying anything.

Interest in Claude among small operators is high enough that Anthropic changed its startup offers, which I covered in Anthropic Pauses Free Claude Team and $1,000 Credits. High demand is exactly what makes a brand a good lure.

Claude Malvertising Puts Your Shopify and Ads Logins at Risk

My read: the brand on the lure will keep changing, and your store’s exposure comes from the habit, not the brand. Trend Micro found six or more brands impersonated in one campaign. The tools a store owner searches for every month, such as Klaviyo, a Shopify app, a shipping label tool or an AI assistant, are candidates for the same treatment. If you do not remember typing the address, assume the search ad could be anything.

The final payload here is unknown, so I will not claim what it steals. The earlier InstallFix wave used a credential stealer, per Dark Reading. If a stealer lands on the laptop where you or a VA stay logged in to Shopify, Google Ads and a bank, the browser sessions are the prize. My guide to Claude for a leaner high-ticket business says to put an AI assistant to work, and I stand by that. The install just has to come from the vendor, not from an ad.

Run hypothetical math on a store that spends $300 a day on Google. This is my illustration, not a reported loss. An attacker holding a live ads session could change final URLs or raise budgets over a long weekend, and three days at $300 is $900 gone before Monday. Add a hijacked payout or a processor login and the number grows, which is why I keep pushing the payment processor backup plan. Ad spend is also the engine behind a complete high-ticket Google Ads conversion system, so a drained account hurts twice.

High-ticket stores carry one more exposure that a general retailer does not. Your laptop probably holds supplier portal logins with dealer pricing, MAP sheets and authorized-dealer terms. My read is that a stolen session there would show a competitor your cost basis, and no dashboard would flag it. Nothing in the reporting says this payload goes after supplier portals. I am pointing at where the damage would be worst for a dealer, not at a confirmed behavior.

The retailer in the chain is the second lesson. Its site did not get attacked for its customers. It got borrowed as a hop. My read is that any store with an unpatched WordPress plugin, a stale blog or an old microsite can be rented out the same way, and you may never see an alert. Two recent EP stories sit in the same territory. One is the ASOS breach tied to customer messaging platforms. The other is the story on unauthorized Google certificates and locking your store domain.

Your team is the third lesson. If you hire virtual assistants through OnlineJobs.ph, the install rule goes in writing on day one. A VA who searches for a tool because you asked for it at 11pm has the same Google results you do. If you would rather hand the whole build to a team than vet every install yourself, that is what the turnkey done-for-you build is for.

The counterpoint is real. This exact chain targets macOS users who find the ad through Google, and Push says its own customers need no action. If your team runs Windows or never searches for Claude, this specific lure misses you. Trend Micro’s June research covered PowerShell variants, though, and a single observed instance is not a measure of scale. Treat it as a warning about the pattern, not a panic.

Want to compare team access rules with other store owners and me inside the community? Join the Skool community →

Block Fake Installer Ads: Six Steps for Store Teams

Do these six this weekend, in this order:

  1. Write the rule down and send it to everyone with a login: no software installs from search ads, ever. Bookmark the vendor’s address once, and open tools from the bookmark. For Claude, the real site is claude.ai, and my Claude link goes there.
  2. Ban pasting terminal or PowerShell commands copied from a web page. Trend Micro recommends installing developer tools through official package managers such as pip, npm, brew and apt instead of web guides. If a page’s Copy button gives you something you cannot read, close the tab.
  3. Tighten your core accounts. In Google Workspace, turn on 2-step verification for every user, and cut Shopify staff to the permissions each person needs. My walkthrough of the Google Workspace admin console shows where those settings sit.
  4. Prepare the “someone pasted it” plan before it happens. From a clean device, change the passwords, sign out all sessions, and rotate API keys, including those in Klaviyo and any Shopify custom apps. Then run a scan with one of the tools in my antivirus comparison.
  5. Watch the machines and the person. SentryPC can log and block activity on a VA’s work computer. For your own identity, IdentityGuard offers monitoring in case a stealer reaches your devices.
  6. Audit your own site for the borrowed-hop problem. Open your About page in a private window from a Bing search result and a Google search result and check whether it redirects anywhere. Check the Security issues report in Google Search Console, update WordPress plugins, and consider a managed host such as Cloudways that handles server patching so the maintenance is not on your Saturday.

Book a discovery call if you want a second set of eyes on how your store’s logins are set up. Keep business banking on its own device, and if you do not have a dedicated account yet, here is how to open a Mercury account.

Frequently Asked Questions

Is Claude itself compromised?
No. Push and BleepingComputer describe a fake page that imitates Claude, not a breach of Anthropic. In the earlier June campaign, Trend Micro says Anthropic banned the accounts involved and disabled the malicious shared chats.

Does a VPN or antivirus stop this?
A VPN does nothing against a command you paste yourself. Antivirus may catch known payloads, but Push argues that indicator-based detection ages quickly, so the habit of never pasting commands matters more. Compare options in my antivirus guide.

Can I spot the fake ad from the URL?
Not here. The ad displayed bing.com, a real domain, according to BleepingComputer. Open the tool from a bookmark or type the address yourself.

My store is on Shopify. Can my site be used as a hop?
The hop in this case was a WordPress site. Shopify handles server patching for the hosted storefront, but your apps, staff accounts and any separate WordPress blog stay your responsibility. Review them in Shopify and keep plugins updated.

What if someone already pasted the command?
Treat the computer as compromised. Change passwords from a clean device, revoke active sessions, rotate API keys and check bank, ad and email logins for changes. Do not use the infected machine to do any of it.

I have not launched a store yet. Where do I start?
Start with my guide to what high-ticket dropshipping is. Then pick a category from the high-ticket niches list. Set the install rule before you hire anyone or connect a single tool.

Is there a free place to learn the setup order?
Yes. The free mini course covers the basics. For the full sequence, read everything you need to launch a high-ticket business.

Want my team to build and run your high-ticket store for you? See the turnkey done-for-you service →

Subscribe to the YouTube channel for daily breakdowns. More breaking news coming through the day. If you only do one thing from this post, make it the install rule, because it costs nothing and it works against the pattern no matter which brand the next lure wears.

Related Articles

If this was useful, these go deeper:

Free 1,000+ high-ticket niches list

Still deciding what to sell?

Grab the free list of 1,000+ niches that work for high-ticket dropshipping, sorted by category.

Free. Unsubscribe any time.