Fetching from the wire…
Public story · 2026-09-12 · high
The fake error box asks you to copy a fix into a terminal, and the copy runs straight past your instincts.
Why now: Ars Technica reported the campaign spreading across Windows and Mac as of September 12, 2026.
A scam called ClickFix is infecting Windows PCs and Macs by asking people to fix their own machines. A fake error message tells the victim their browser, video player, or document viewer hit a problem, then walks them through the fix: open a terminal or the Windows Run box, paste a command, hit enter. The command is the payload. There's no download prompt, no attachment, no exploit. The user runs the malware themselves, one paste at a time, per Ars Technica.
What makes it work is that it doesn't feel like an attack. It feels like troubleshooting. Anyone who's fixed a stuck npm install or a broken Homebrew tap by pasting a command from a forum post has already rehearsed this exact motion. Ars Technica reports the technique is now infecting Mac users at a scale similar to Windows, and that matters because a lot of security advice for regular users has assumed macOS is a smaller target.
The part that should bother developers specifically: this scam's cover story is a pattern we all ship on purpose. A one-line curl-pipe-to-bash install command is standard onboarding for half the tools I install. It's fast, it's one line, and it's also indistinguishable in spirit from what a ClickFix lure asks a victim to do. I'm not saying every install script is a threat. I'm saying we've spent years training users that pasting an unread command into a shell is a normal Tuesday, and this campaign is what happens when that training gets pointed at them by someone else.
A signed installer or a package manager entry doesn't stop a determined attacker from finding another vector. But it does mean your project isn't the thing that made "paste this to fix it" feel routine.
Each link below shares sources, entities, or timing with this story.
Google released Antigravity IDE Extensions, putting its agentic coding platform into VS Code (macOS, Linux, Windows), JetBrains IDEs from 2026.2.1 (IntelliJ, PyCharm, WebStorm, GoLand, CLion, Rider), Zed, and Visual Studio 2026 in preview. One Antigravity account works everywh...
Tagged September 9 with isolated checkouts for new or forked sessions plus browse and resume across them. The release also lets you answer questions inline while Codex keeps working without losing your main draft, and gives Windows sessions a shared background Codex server wit...
Imported sessions are marked with their source tool and the foreign transcript is summarized once on the first resumed turn, because imported histories carry the original tool's tool names and schemas that a continuing model may try to call. The loop detector's decision callba...
The agent-security topic holds 42 repos above 100 stars, four from large companies rather than startups: NVIDIA/SkillSpector (14,498 stars, scanning Claude Code/Codex/MCP skills for prompt injection), Tencent/AI-Infra-Guard (4,467, red-teaming with Many-Shot/PAIR/GOAT/ActorAtt...
msitarzewski/agency-agents added 446 stars today, packaging personas across "divisions" (frontend specialists, community experts, fact-checkers, reality checkers), each defined with a voice, a process, and concrete deliverables rather than a generic prompt template (GitHub). I...
github.com/perplexityai/numbat shipped v0.1.1 on July 29 at 239 stars, Apache 2.0, a single cgo-free Go binary for macOS/Linux/Windows. It observes Claude Code, Codex, OpenCode, and Pi through local hooks, OTLP/HTTP log exporters, and on-disk session artifacts, normalizes into...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.