A user reportedly got infected after following a download link provided by Claude. After wiping the laptop, they found a malicious SKILL.md that could potentially reinfect the system through Claude Code and steal credentials. A worrying look at how AI agents can become a new malware and supply-chain attack surface.
a user said they were compromised after asking Claude for help installing a transcription application
Yeah, maybe computers aren’t for you.
“oh no! I let predictive text full root access to my computer and it put a virus on it!”
I’ve seen a lot of LLM sites popping up that purport to be project pages for Open Source projects. They’re of course full of malicious links instead. Guess this is an extension of that. Can’t say I don’t feel some Schadenfreude.
Whats worse is a lot of them have hidden prompts which poison LLMs…so anybody trying to Analyse their source code with the help of any LLM will find no red flags. Manually human verification is required
Whenever developer added a new executing layer on a system, malicious people started to exploit it. Mcromedia Flash, Java, JavaScript, and now AI usage.
Yeah, that’s self-inflicted





