Live data from Hacker News

Malicious skills targeting Claude Code and Moltbot users

opensourcemalware.com

11–20 of 92 posts

Re: Malicious skills targeting Claude Code and Moltbot users

#11
This is funny, I was discussing moltbook with Claude and it told me there's already a crypto. I thought that's pretty funny, I might want to get some, but can't be arsed to figure it out.

"Do you think I could just give molt a BTC wallet with a bit of funds and tell it to figure out how to buy some?"

-"Yes, but it wouldn't be long before you get pwned."

... Six hours later, this pops on the front page :)

Re: Malicious skills targeting Claude Code and Moltbot users

#12
post #10

I've heard people granting access to their production servers to this thing. Apparently you can ask it to check logs to find solutions to some errors or whatever. Gotta be a complete moron to do that. I've only installed it on a fresh VM and the first impression was underwhelming. Maybe there is some magic I can't see.

Putting it on a VPS is genius. Putting it on a VPS you rely on... Yeah maybe not ;)

Re: Malicious skills targeting Claude Code and Moltbot users

#16

I'd call it "suspicious" that this latest idiocy came out of nowhere and got pushed so hard to normies, when results like this are 100% predictable... if it wasn't also consistent with how the AI industry itself operates.

It really is a huge bummer that the most important new technologies of this era have such a film of slime on them. Crypto, AI, whatever comes next, it's just no longer an era in which we can expect innovation to make our lives better. It enables grifters and scammers more than anyone else.

Re: Malicious skills targeting Claude Code and Moltbot users

#17
post #3

Anyone dumb enough to run this on their computer deserves it.

I think most people are buying separate computers to run it on. This is a nice example of why you might want to do that.

(Though they're still hooking it up to their entire digital life, which also doesn't seem very reassuring.)

Re: Malicious skills targeting Claude Code and Moltbot users

#20
Ok I ask chat GPT sometimes for advice in health / Fitness and also finance. Not like where to put my money but for general Information how stuff works what would apply here and there. The issue is already that OpenAI knows a lot of me. And ChatGPT itself when asked what he things I am etc draws a pretty clear picture. But I stay away from oversharing specific things. That is mainly my income and other super detailed data. When I ask I try to formulate it to use simple numbers and examples. Works for me. When working with coding agents I’m very skeptical to whitelist stuff. It takes quite the while before I allow a generic command to be executed outside of a sandbox. But to install a random skill to help with Finance Automation… can’t belief it. Under what stone do you have to live to trust your money be handed by an agent and then also in connection with a random skill?
Post reply on HN