“My guess is that the Reddit account is compromised,” a Reddit security sleuth wrote after finding a verified HBO Max post used to deliver a download that instructed macOS users to paste a command into Terminal — the classic ClickFix vector that researchers say drove a short, intense malvertising campaign.
How the HBO Max Reddit account was used
On September 6 a Reddit user discovered an ad that showed u/hbomax as the author and advertised a macOS app for HBO Max — despite the streaming service not offering a native Mac client. Clicking the ad directed visitors to a landing page at hbomaxx[.]us with a join/download button. According to the sleuth’s testing in a sandboxed environment, the download flow produced instructions that told macOS users to copy and paste a command into Terminal, a hallmark of ClickFix-style infostealer delivery. The researcher said they did not run the executable in their environment.
The PasteSwitch malvertising blitz
Researchers at Hudson Rock and ADAMnetworks analyzed the activity and described it as part of a “massive 48-hour malvertising blitz” that pushed 108 distinct ads using multiple software lures. The two teams gave the operation the name PasteSwitch. Of the 108 ads, 46 used HBO Max-themed lures directing victims to hbomaxx[.]app or hbomax-macos[.]com; 36 used an OpenAI Codex theme that routed to codex-craft[.]com; 15 purported to be a macOS disk utility at apple.clean-disk-guide[.]com; and 11 used developer-tool lures via code-desktop[.]com.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTechnical mechanics: ClickFix, infostealers and blockchain-based C2
Hudson Rock and ADAMnetworks reported that PasteSwitch served targeted payloads for both Windows and macOS. The delivered software included information-stealing malware (infostealers), malware loaders, cryptocurrency clippers (identified as either AnimateClipper or ZigClipper), and fake cryptocurrency wallet applications. The campaign relied heavily on ClickFix social engineering — persuading targets to paste a command into a terminal to fetch and run code — and used multiple lures (developer tools, disk cleaners, AI tools and streaming apps) to increase reach.
Notably, the cryptocurrency clippers employed blockchain-based command-and-control fallbacks. The researchers said the attackers used Binance Smart Chain (BSC) contracts to let the malware dynamically fetch whatever C2 domain the operators were using at a given moment. Hudson Rock reported that “between March and July 2026, researchers observed 36 mainnet changes executed by the same attacker controller address,” and that hosting the C2 domain on-chain gives the infrastructure “dynamic resilience, allowing the threat actors to easily rotate burned domains.”
Timeline and platform response: Reddit paused ads; HBO Max parent silent
The Register’s timeline shows the ads were uncovered on September 6; three days later Reddit paused the infostealer-dropping ads. A Reddit administrator said the platform’s safety and security teams were investigating the incident. Warner Bros. Discovery, HBO Max’s parent company, did not immediately respond to The Register’s inquiries about who hijacked the Reddit account or how the takeover occurred.
What this means for Reddit users, Warner Bros. Discovery and security teams
- Reddit users and the general public: The PasteSwitch flow demonstrates how a verified account can be used to push a seemingly legitimate app download and then instruct users to execute commands locally. Users encountering offers for software that asks them to paste commands into Terminal or run installers from non-official domains should treat those flows as high risk.
- Warner Bros. Discovery / HBO Max: The presence of a verified account in the campaign indicates an account takeover or misuse; the company’s lack of comment to The Register leaves questions about how the account was compromised and what remediation steps have been taken.
- Security teams and researchers: PasteSwitch reinforces that trusted distribution channels and advertising ecosystems are attractive delivery vectors. The combination of ClickFix social engineering and blockchain-based C2 fallback mechanisms — including 36 observed mainnet changes linked to a single controller address — will complicate takedowns and tracking of active domains.
As researchers at Hudson Rock and ADAMnetworks continue to map PasteSwitch’s infrastructure and lures, two questions remain central: which credentials or controls allowed the verified HBO Max account to be used for malvertising, and how quickly can advertising networks and platform operators respond to campaigns that pair social engineering with blockchain-backed resilience? Reddit has said its teams are investigating; Warner Bros. Discovery has not replied to inquiries at the time of publication.




