• Wow, grabbing a base64 obfuscated URL with curl sending the output to bash is a huge red flag. I guess Mac users must not know anything about the CLI.

    Never pipe the output of curl or wget to bash. You can’t inspect whatever it downloads before it gets run. If the URL is obfuscated, there is basically a 100% chance that it’s malicious.

    • 2 months

      If you know what curl is, you’re not the target audience.

      The people this is targeting don’t even know what ‘CLI’ stands for, but they absolutely will copy/paste random commands into their computer if they’re told it’ll magically fix something.

    • 2 months

      Can’t imagine why you think that’s exclusive to Mac users. Basically no one knows how computers work

  • whereIsTamara@lemmy.orgBanned from communityEnglish
    2 months

    I bet they’re hoping dumb LLMs read it and spit it back out.

  • An ad blocker would have stopped this, which is why it is a matter of cybersecurity best practices to always employ a proper ad blocker.