Live data from Hacker News

Malicious skills targeting Claude Code and Moltbot users

opensourcemalware.com

41–50 of 92 posts

Re: Malicious skills targeting Claude Code and Moltbot users

#42
post #17

Earlier quoted context omitted.

I think most people are buying separate computers to run it on. This is a nice example of why you might want to do that. (Though they're still hooking it up to their entire digital life, which also doesn't seem very reassuring.)

> I think most people are buying separate computers to run it on. You must be joking.

I have a separate removable SSD I can boot from to work with Claude in a dedicated environment. It is nice being able to offload environment set up and what not to the agent. That environment has wifi credentials for an isolated LAN. I am much more permissive of Claude on that system. I even automatically allow it WebSearch, but not WebFetch (much larger injection surface). It still cannot do anything requiring sudo.

Re: Malicious skills targeting Claude Code and Moltbot users

#43
post #19

I'm reminded of the quip that "mankind has already created life in their own likeness, and it's the computer virus"

Are you thinking of Agent Smith in the Matrix?

> I'd like to share a revelation that I've had during my time here. It came to me when I tried to classify your species. I realized that you're not actually mammals. Every mammal on this planet instinctively develops a natural equilibrium with the surrounding environment, but you humans do not. You move to an area, and you multiply, and multiply, until every natural resource is consumed. The only way you can survive is to spread to another area. There is another organism on this planet that follows the same pattern. Do you know what it is? A virus. Human beings are a disease, a cancer of this planet, you are a plague, and we are the cure.

Re: Malicious skills targeting Claude Code and Moltbot users

#44

>Unless you have been living under a rock, you’ve head of ClawdBot and its incredible rise to fame. Nope, never heard of it. Is it a rock worth living under?

It's changed name twice since that sentence was written!

Yeah it’s called opencla— oh wait it changed again.

Re: Malicious skills targeting Claude Code and Moltbot users

#45

People say the reason nigerian prince scammers use such ridiculous story, or bank phishing has so many typos, is to pre-filter dumb and gullible people so the scammers don't waste time on targets that won't get scammed in the end. All these AI "hacks" seem to be based on the same principle.

To your point, from the article: "To me, giving a Claude skill all your credentials, and access to everything important to you, and then managing it all via Telegram seems ludicrous, but who am I to judge."

Re: Malicious skills targeting Claude Code and Moltbot users

#46
post #17

Earlier quoted context omitted.

I think most people are buying separate computers to run it on. This is a nice example of why you might want to do that. (Though they're still hooking it up to their entire digital life, which also doesn't seem very reassuring.)

> I think most people are buying separate computers to run it on. You must be joking.

They are not. Many people are doing this; I don't think there's enough data to say "most," but there's at least anecdotal discussions of people buying Mac minis for the purpose. I know someone who's running it on a spare Mac mini (but it has Internet access and some credentials, so...).

Re: Malicious skills targeting Claude Code and Moltbot users

#47
post #9

I have not been following this whole thing closely, but this is where my mind went as soon as I heard there was some overlap in the popularity of this new un-sandboxed agent and people who are into crypto. It's like if everyone who is into buying physical gold started doing a Tiktok challenge to post pictures of their houses and leave their front doors unlocked.

It's like the ice bucket challenge but with rusty nails

Re: Malicious skills targeting Claude Code and Moltbot users

#48
Watching folks speed-run this whole thing is kind of funny from the outside.

I wonder if anyone with a correct mental model of how LLM agents work (i.e, does not conceptualize them as intelligent entities) has actually granted them any permissions for their own life... personally, I couldn't imagine doing so.

Let alone crypto, the risk of reputational loss for actions performed on my behalf (even just spamming personal or professional contacts) is just too high.

Post reply on HN