Earlier quoted context omitted.
[flagged]
What commonly gets installed in those cases is actual malware, a RAT (Remote Admin Tool) that lets the attacker later run commands on your laptop (kinda like an OpenSSH server, but also punching a hole through nat and with a server that they can broadcast commands broadly to the entire fleet). If the attacker wants to use AI to assist in looking for valuables on your machine, they won't install AI on your machine, th…
Actually they’ll just the AI you already have on your machine[0]
In this attack, the malware would use Claude Code (with your credentials) to scan your own machine.
Much easier than running the inference themselves!
[0]https://semgrep.dev/blog/2025/security-alert-nx-compromised-...