What happened
Hudson Rock and ADAMnetworks researchers found 108 malicious ads from compromised u/hbomax over 48 hours in September 2026, exposing the PasteSwitch ClickFix operation across five lure domains.
A verified HBO Max account on Reddit was compromised and used to run 108 ClickFix ads in just 48 hours, spanning hbomaxx.app, codex-craft.com and three other lure sites.
ClickFix shows a fake error asking you to copy a command into Terminal or Command Prompt. That command — not a download — installs the malware, so antivirus often misses it.
On Mac the payload is MacSync and AMOS via curl | zsh stealing browser logins and Telegram data. On Windows mshta runs an MP3/HTA polyglot, disables AMSI, and injects Amatera Stealer straight into memory.
Crypto holders face extra risk: fake wallet apps steal 12/24-word phrases and clipboard clippers swap addresses using Binance Smart Chain contracts rotated 36 times since March 2026.
What is confirmed
Reddit confirmed the HBO Max ad account was compromised, locked it and removed ads. Researchers confirmed PasteSwitch infrastructure across macOS and Windows with contract-controlled clippers.
- 108 ads in 48 hours from u/hbomax — 40 via hbomaxx.app, 36 via codex-craft.com, others via apple.clean-disk-guide.com, code-desktop.com, hbomax-macos.com
- Amatera uses Schannel manual cert validation and SNI spoofing to 77.91.65.13:443 as facebook.com
- Binance Smart Chain AnimateClipper/ZigClipper rotated 36 times — verifiable on-chain
What to do now
If you pasted a command, treat the device as compromised. Do not paste commands from websites into Terminal or Run dialogs.
- Change passwords from a clean device, enable 2FA, revoke wallet approvals, and run a full malware scan
- For admins: block mshta execution, monitor curl | zsh and AMSI tampering, filter SNI anomalies to 77.91.65.13
Why it matters for me
Anyone who pasted the fake fix command into Terminal or Command Prompt silently installed MacSync, AMOS or Amatera stealers that steal passwords, Telegram data and crypto wallets without a download.
Privacy
General Internet Users
Browser passwords, Telegram data and macOS keychain can be stolen in seconds if you run the pasted command — even without downloading a file.
Money
Cryptocurrency Holders
Fake wallet apps and clipboard clippers swap your crypto address mid-transaction — funds can be redirected to attacker contracts on Binance Smart Chain.
Work
Software Developers
User-executed terminal commands bypass antivirus and download filters, so developers and IT teams need to train users never to paste unverified commands.
What to remember
Never copy-paste a fix from a website into Terminal — that is the hack.
108 fake HBO ads tricked users into hacking themselves — a paste into Terminal stole passwords and crypto. Never paste fixes from the web.
Verified sources (4)
ClickFix attacks are tricking Mac and Windows users into hacking themselves
↗HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation
↗HBO Max ads exposed the PasteSwitch ClickFix operation
↗Reddit administrator confirmation that malicious ads have been paused
↗Claims and linked sources
8 claimsClickFix attacks have evolved from rare 2026 curiosities into a massive international operation that tricks victims on both Mac and Windows into copying and pasting malicious terminal commands to hack themselves.
In September 2026 the verified official u/hbomax Reddit account was compromised and used to push 108 malicious ClickFix ads over 48 hours across five lure destinations: hbomaxx.app (40), codex-craft.com (36), apple.clean-disk-guide.com (15), code-desktop.com (11) and hbomax-macos.com (6).
The HBO Max ads exposed PasteSwitch, a cross-platform ClickFix operation spanning MacSync and AMOS macOS stealers, InstallFix and Amatera Windows loaders, deceptive TLS SNI spoofing (Amatera connects to 77.91.65.13:443 presenting facebook.com), fake wallet apps, and Binance Smart Chain contract-controlled crypto clippers.
On Windows PasteSwitch delivers InstallFix via mshta that downloads an MP3/HTA polyglot, creates a scheduled task, launches 32-bit PowerShell, disables AMSI, computes a victim-specific subdomain from computer name and username, and injects Amatera Stealer PE directly into memory without touching disk.
PasteSwitch crypto clippers AnimateClipper and ZigClipper use Binance Smart Chain smart contracts as mutable C2 dead drops via getData() and balanceOf(address), with 36 mainnet C2 rotations by the same controller between March and July 2026.
Because the malware is executed directly from Windows Command Prompt or macOS Terminal — a trusted OS interface — many ClickFix attacks evade antivirus and browser download protections that would block downloaded binaries.
Reddit told TechCrunch it learned an HBO Max account authorized to run ads was compromised and used for malicious links, and that it locked the account and removed the ads; an admin publicly confirmed the ads were paused.
The macOS branch delivers MacSync (exfiltrates browser credentials, Gecko profiles, Telegram data, Apple Notes, passwords via /tmp/osalogging.zip) and AMOS Helper (persists under .com.apple.accountsd, enrolls via /api/join/ and /api/tasks/) through curl | zsh commands.
Community signals
Signal-only · not reporting“The ads have been paused and the account locked after compromise was detected.”