Malware was spreading through a sponsored ad on X.
@JamfThreatLabs caught a ClickFix attack posing as DynamicLake, a legit Mac app.
It ran from a verified account with a fairly large following, sending users to a lookalike domain that told them to paste install code into Terminal 🙈
It's since been removed. But the bigger story is how X let this happen 👇