Live data from Hacker News

Malicious skills targeting Claude Code and Moltbot users

opensourcemalware.com

31–40 of 92 posts

Re: Malicious skills targeting Claude Code and Moltbot users

#31
post #3

Anyone dumb enough to run this on their computer deserves it.

AI has developed this entire culture of people who are "into tech" but seem to not understand how a computer works in a meaningful way. At the very least you'd think they'd ask a chatbot if what they're doing is a bad idea!

Re: Malicious skills targeting Claude Code and Moltbot users

#34
> I don’t know how many people are involved in managing the ClawHub registry, but there is no evidence that the skills listed there are scanned by any security tooling. Many of the payloads we found were visible in plain text in the first paragraph of the SKILL.md file.

I shouldn't still be shocked by the incompetence and/or negligence of these people, and yet I am.

Re: Malicious skills targeting Claude Code and Moltbot users

#35
People say the reason nigerian prince scammers use such ridiculous story, or bank phishing has so many typos, is to pre-filter dumb and gullible people so the scammers don't waste time on targets that won't get scammed in the end.

All these AI "hacks" seem to be based on the same principle.

Re: Malicious skills targeting Claude Code and Moltbot users

#36
post #3

Anyone dumb enough to run this on their computer deserves it.

AI has developed this entire culture of people who are "into tech" but seem to not understand how a computer works in a meaningful way. At the very least you'd think they'd ask a chatbot if what they're doing is a bad idea!

> AI has developed this entire culture of people who are "into tech" but seem to not understand how a computer works in a meaningful way.

Isn't that the whole point of AI?

Re: Malicious skills targeting Claude Code and Moltbot users

#37
post #20

Ok I ask chat GPT sometimes for advice in health / Fitness and also finance. Not like where to put my money but for general Information how stuff works what would apply here and there. The issue is already that OpenAI knows a lot of me. And ChatGPT itself when asked what he things I am etc draws a pretty clear picture. But I stay away from oversharing specific things. That is mainly my income and other super detailed…

> draws a pretty clear picture

You have "memory" activated in your settings. It is recording information about you and using it in future conversations. Have a look at settings > personalization

Re: Malicious skills targeting Claude Code and Moltbot users

#38
post #10

I've heard people granting access to their production servers to this thing. Apparently you can ask it to check logs to find solutions to some errors or whatever. Gotta be a complete moron to do that. I've only installed it on a fresh VM and the first impression was underwhelming. Maybe there is some magic I can't see.

Bad news is there are such morons in your company.

Good news is this is why we have IAM and why such people in my org don't get any production access.

Post reply on HN