A user reportedly got infected after following a download link provided by Claude. After wiping the laptop, they found a malicious SKILL.md that could potentially reinfect the system through Claude Code and steal credentials. A worrying look at how AI agents can become a new malware and supply-chain attack surface.

  • nightlily@leminal.space
    link
    fedilink
    English
    arrow-up
    15
    ·
    3 days ago

    I’ve seen a lot of LLM sites popping up that purport to be project pages for Open Source projects. They’re of course full of malicious links instead. Guess this is an extension of that. Can’t say I don’t feel some Schadenfreude.

    • UnLocoPoco@lemmy.worldOP
      link
      fedilink
      arrow-up
      1
      ·
      2 days ago

      Whats worse is a lot of them have hidden prompts which poison LLMs…so anybody trying to Analyse their source code with the help of any LLM will find no red flags. Manually human verification is required