Tendvane

← All articles

SecurityOctober 10, 2026

The ad said it was taking you to Bing. It did take you to Bing, briefly.

The ad looked fine. Someone searching Google for "claude mac" got a sponsored result whose visible destination was bing.com, which is about as unalarming as a link gets. Clicking it did reach Bing. It just did not stop there.

Push Security pulled the chain apart and gave the trick a name: Adception. The click went through Google's own ad redirect, into Bing's click tracker at bing.com/ck/a, out to the hacked WordPress site of a South American retailer, and finally to claude-desk-code[.]com, a copy of Anthropic's download page. Showing Bing as the destination is what got the ad past Google's review in the first place. The hacked shop then added a filter of its own, passing visitors along only if they had arrived from Bing with the expected browser headers, and the fake page returned a flat 404 to anything that smelled like a security scanner.

What waited at the end was the clipboard trick. The page displayed Anthropic's real install command while the copy button quietly loaded a different one, a base64 string that pulls down a file and runs it. This particular campaign was built for Mac users, so a Windows PC following the same ad would have come away with nothing. The laundering is the part to pay attention to, because it works no matter which operating system the fake page is dressed up for, and the next one will be dressed for Windows.

Judging an ad by the domain it shows you no longer tells you much. The better habit is to stop using search results for downloads at all: type the vendor's address yourself, or let something else do the fetching. Tendvane updates the apps you already have through winget, Microsoft's own package source, so there is no search result in the chain to poison.

Sources

Download Tendvane