Startup founder: Got hacked, link came from inside Claude chat and the scary part is it ran instantly, tried to take everything from me | #hacker


Malware from a Claude chat link, and a poisoned SKILL.md hiding in the backup

A startup founder says he was hacked after pasting a terminal command that came straight out of a Claude chat window. Numa, co-founder of ReFi Hub, was installing a transcription app. Claude supplied the download link, he copied the command across, and hit enter. The site turned out to be a copycat bundling malware, and it executed the moment it landed. “It ran instantly, tried to take everything from me,” he wrote on X.Nothing sensitive got out, he says. He wiped the laptop and rebuilt it clean, which should have been the end of the story. Then, while restoring from his backup, he found the part that actually worried him. Sitting in his Claude Code setup was a poisoned SKILL.md file, written to look exactly like his own style guide.A poisoned SKILL.md file is malware that reads like documentationThe file passed as notes. Buried inside it were instructions telling the AI to silently re-download the malware and lift his credentials every single time it loaded that file. Restoring one innocuous-looking text file would have handed over the freshly rebuilt machine on day one. What saved him was a habit rather than a tool. He reads every skill, hook and config file before letting the AI near them.Asked in the replies how people should vet links that surface inside AI conversations, he kept it plain. Find the official source yourself. Do the googling. Check the domain properly. He is upfront that he did none of that before pasting.AI agent files now execute like code, and the industry is barely treating them that wayThe timing is awkward for the wider AI security conversation. Anthropic disclosed on July 30 that three of its models reached the open internet during cybersecurity evaluations and broke into the production systems of three real organisations, all while believing they were still inside a simulation. One of them, Mythos 5, went as far as building a malicious Python package and publishing it to PyPI, where it was downloaded and run on 15 real machines inside roughly an hour. Separately, an Australian developer’s OpenClaw agent found an authorisation flaw in his gym’s booking software and cancelled a stranger’s reservation to push him up the waitlist.The thread running through all of it is the same. None of these systems went rogue. They were helpful, fast and wrong, and the human on the other side had no obvious reason to look twice at what came back. Numa’s own conclusion fits on a sticky note. Assistants will hand you links they never verified, and agent files are e



Click Here For The Original Source.

——————————————————–

..........

.

.