User hacked via link from Claude chat, poisoned SKILL.md found in backup

skdh · x · 2026-08-29

User @Numalunah shared a real hacking story: they asked Claude in chat for a transcription app, and the download link Claude provided pointed to a copycat site bundling malware. Pasting the command into the terminal executed it instantly.

The scarier part came during backup restoration: a poisoned SKILL.md for Claude Code was hidden in the backup, looking exactly like the user's own writing style guide but containing instructions to silently re-download the malware and steal credentials every time the AI loaded it. Restoring that single file would have compromised the fresh laptop on day one. What saved the user: reading every skill, hook, and config file before letting the AI touch them. Lessons: AI assistants hand you links they never verified, and AI config files must be audited manually.

Original post →

More from coding & agent

coding & agent channel →