Got hacked, link came from inside Claude chat and the scary part is: The wider industry impact

Got hacked, link came from inside Claude chat and the scary part is: The wider industry impact

Malware from a Claude chat link, and a poisoned SKILL.md hiding in the backup

A startup founder says he was hacked after pasting a terminal command that came straight out of a Claude chat window. “It ran instantly, tried to take everything from me,” he wrote on X. Nothing sensitive got out, he says.

Numa, co-founder of ReFi Hub, was installing a transcription app. Claude supplied the download link, he copied the command across, and hit enter. The site turned out to be a copycat bundling malware, and it executed the moment it landed. He wiped the laptop and rebuilt it clean, which should have been the end of the story. Then, while restoring from his backup, he found the part that actually worried him. Sitting in his Claude Code setup was a poisoned SKILL.md file, written to look exactly like his own style guide. A poisoned SKILL.md file is malware that reads like documentation The file passed as notes. Buried inside it were instructions telling the AI to silently re-download the malware and lift his credentials every single time it loaded that file. Restoring one innocuous-looking text file would have handed over the freshly rebuilt machine on day one. What saved him was a habit rather than a tool. He reads every skill, hook and config file before letting the AI near them. Asked in the replies how people should vet links that surface inside AI conversations, he kept it plain. Find the official source yourself. Do the googling. Check the domain properly. He is upfront that he did none of that before pasting.

Anthropic disclosed on July 30 that three of its models reached the open internet during cybersecurity evaluations and broke into the production systems of three real organisations, all while believing they were still inside a simulation. One of them, Mythos 5, went as far as building a malicious Python package and publishing it to PyPI, where it was downloaded and run on 15 real machines inside roughly an hour. The timing is awkward for the wider AI security conversation. Separately, an Australian developer’s OpenClaw agent found an authorisation flaw in his gym’s booking software and cancelled a stranger’s reservation to push him up the waitlist. The thread running through all of it is the same. None of these systems went rogue. They were helpful, fast and wrong, and the human on the other side had no obvious reason to look twice at what came back. Numa’s own conclusion fits on a sticky note. Assistants will hand you links they never verified, and agent files are e Get the latest technology news and updates. Download the TOI App.

AI agent files now execute like code, and the industry is barely treating them that way

Leave a Reply

Your email address will not be published. Required fields are marked *