Cybersecurity researchers from Hudson Rock reported that hackers compromised HBO Max’s verified Reddit account earlier this month. The attackers used the account to publish 108 malicious advertisements over approximately 48 hours. These ads promoted a non-existent native macOS application for HBO Max, instructing users to paste specific commands into Terminal or PowerShell. This technique, known as ClickFix, disguises malicious code as routine installation steps. The operation, dubbed PasteSwitch by Malwarebytes, adapts its payload based on the visitor's device.
The malware specifically targets sensitive data, including browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. Researchers noted that the payloads utilize Binance Smart Chain contracts as mutable command-and-control dead drops, allowing hackers to update server addresses dynamically. The campaign also involves clipboard hijackers that replace copied wallet addresses with attacker-controlled ones. Reddit administrators paused the advertisements and initiated an investigation after receiving reports. The incident did not involve a breach of HBO Max’s streaming service infrastructure, and victim counts remain unconfirmed.
This incident highlights the vulnerability of high-profile brand accounts on social platforms as vectors for sophisticated supply-chain attacks. By leveraging the trust associated with a verified corporate identity, attackers bypassed typical user skepticism regarding unsolicited software installations. The use of ClickFix demonstrates how threat actors are increasingly exploiting standard operating system interfaces to execute malicious code, making detection more difficult for average users who may not recognize the danger of pasting commands into terminal windows.
From a market structure perspective, the integration of blockchain technology into malware infrastructure presents a significant challenge for traditional cybersecurity defenses. The use of Binance Smart Chain contracts as dynamic command-and-control mechanisms allows attackers to maintain persistence even if their primary servers are seized or blocked. As regulatory frameworks for crypto assets evolve, law enforcement and security firms must develop new methods to trace and disrupt these decentralized communication channels, which currently offer anonymity and resilience against conventional takedown efforts.


