A user reportedly got infected after following a download link provided by Claude. After wiping the laptop, they found a malicious SKILL.md that could potentially reinfect the system through Claude Code and steal credentials. A worrying look at how AI agents can become a new malware and supply-chain attack surface.

  • UnLocoPoco@lemmy.worldOP
    link
    fedilink
    arrow-up
    1
    ·
    1 天前

    Whats worse is a lot of them have hidden prompts which poison LLMs…so anybody trying to Analyse their source code with the help of any LLM will find no red flags. Manually human verification is required