A user reportedly got infected after following a download link provided by Claude. After wiping the laptop, they found a malicious SKILL.md that could potentially reinfect the system through Claude Code and steal credentials. A worrying look at how AI agents can become a new malware and supply-chain attack surface.



Whenever developer added a new executing layer on a system, malicious people started to exploit it. Mcromedia Flash, Java, JavaScript, and now AI usage.