Cybersecurity researchers from Hudson Rock reported that hackers compromised HBO Max’s verified Reddit account earlier this month. The attackers used the account to publish 108 malicious advertisements over approximately 48 hours. These ads promoted a non-existent native macOS application for HBO Max, instructing users to paste specific commands into Terminal or PowerShell. This technique, known as ClickFix, disguises malicious code as routine installation steps. The operation, dubbed PasteSwitch by Malwarebytes, adapts its payload based on the visitor's device.

The malware specifically targets sensitive data, including browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. Researchers noted that the payloads utilize Binance Smart Chain contracts as mutable command-and-control dead drops, allowing hackers to update server addresses dynamically. The campaign also involves clipboard hijackers that replace copied wallet addresses with attacker-controlled ones. Reddit administrators paused the advertisements and initiated an investigation after receiving reports. The incident did not involve a breach of HBO Max’s streaming service infrastructure, and victim counts remain unconfirmed.