June 12-19 attacks used 22 unique Google Ads campaign IDs to steer Claude-related searches to public claude.ai shared chats that told macOS users to paste Terminal commands, Zscaler said.
Those commands installed MacSync Stealer, malware that can steal credentials, sensitive files and cryptocurrency wallet data; the malicious shared chats were no longer accessible when Zscaler published its July 15 report.
The lure worked because the pages sat on legitimate claude.ai URLs, showing how a normal sharing feature can make malicious instructions appear trustworthy even though Claude itself was not compromised.
Separate reporting has shown the exposure extends beyond one campaign: Google had indexed nearly 600 Claude chats in 2025, and Obsidian Security counted more than 143,000 publicly accessible GenAI conversations across multiple platforms.
Trend Micro linked a related abuse campaign to victims concentrated in Asia-Pacific, while the broader lesson is that shared AI chat links should be treated as public and any exposed keys rotated immediately.