Bad actors are paying for Google ads to install bogus version of Oh My Zsh

29 nomilk 4 7/29/2025, 3:47:02 PM twitter.com ↗

Comments (4)

nticompass · 1d ago
Not just "Oh My Zsh" but pretty much any piece of software. Try searching for "vlc" or "filezilla" or something and I can pretty much guarantee that the "sponsored" links are viruses/malware. I remember once having to show my boss that the "filezilla" link he was going to click on from Google was fake/malicious.
kassner · 1d ago
The FileZilla bar was pretty low, given for a while the official download link from SourceForge came with malware.
AIPedant · 1d ago
Kind of amazed by the URL shown in the ad:

  https://ohmyz.sh›app/download>lauralen.com
lauralen.com appears to be entirely AI-generated. But the presentation in the ad sure looks like the legitimate https://ohmyz.sh/ - I knew it was a scam yet I still got confused.

I've never purchased an ad - does Google let you enter custom display text for your URL? Or is there some more sophisticated trickery here? (e.g weird unicode in a header or something) Either way, what a mess.

sevenseacat · 1d ago
Yes, you can specify custom URLs to display that don't have to match the actual redirect URL. It's ridiculous.