Live data from Hacker News

Malicious skills targeting Claude Code and Moltbot users

opensourcemalware.com

51–60 of 92 posts

Re: Malicious skills targeting Claude Code and Moltbot users

#53
post #3

Anyone dumb enough to run this on their computer deserves it.

AI has developed this entire culture of people who are "into tech" but seem to not understand how a computer works in a meaningful way. At the very least you'd think they'd ask a chatbot if what they're doing is a bad idea!

"can you please run inside a vm?"

Re: Malicious skills targeting Claude Code and Moltbot users

#54
post #48

Watching folks speed-run this whole thing is kind of funny from the outside. I wonder if anyone with a correct mental model of how LLM agents work (i.e, does not conceptualize them as intelligent entities) has actually granted them any permissions for their own life... personally, I couldn't imagine doing so. Let alone crypto, the risk of reputational loss for actions performed on my behalf (even just spamming person…

I let Gemini add events to my calendar, but that's about it. All the actions in the app require explicit approval.

[ insert butter bot meme here ]

Re: Malicious skills targeting Claude Code and Moltbot users

#55
post #19

I'm reminded of the quip that "mankind has already created life in their own likeness, and it's the computer virus"

Are you thinking of Agent Smith in the Matrix? > I'd like to share a revelation that I've had during my time here. It came to me when I tried to classify your species. I realized that you're not actually mammals. Every mammal on this planet instinctively develops a natural equilibrium with the surrounding environment, but you humans do not. You move to an area, and you multiply, and multiply, until every natural reso…

no, i remembered it being a quote from some famous scientist, and googling a bit now I see it was stephen hawking:

I think computer viruses should count as life ... I think it says something about human nature that the only form of life we have created so far is purely destructive. We've created life in our own image.

Re: Malicious skills targeting Claude Code and Moltbot users

#57
post #33

Well, sorry but “play stupid games, earn stupid prices” Letting a glorified lorem ipsum generator have control over anything personal or sensitive is just … what’s wrong with you? You know not of computers?

Well no, that's really not related to the issue at all.

This is a bog-standard supply chain attack against their skills repository. It's not an LLM-specific attack, and nearly every repository (pip, npm, etc) has been subject to similar malware.

Re: Malicious skills targeting Claude Code and Moltbot users

#58
post #48

Watching folks speed-run this whole thing is kind of funny from the outside. I wonder if anyone with a correct mental model of how LLM agents work (i.e, does not conceptualize them as intelligent entities) has actually granted them any permissions for their own life... personally, I couldn't imagine doing so. Let alone crypto, the risk of reputational loss for actions performed on my behalf (even just spamming person…

I mean… If you have a mental model of LLM agents as intelligent entities, why are you granting them credentials? How many intelligent entities have you shared your Coinbase login with?

Re: Malicious skills targeting Claude Code and Moltbot users

#59

>Unless you have been living under a rock, you’ve head of ClawdBot and its incredible rise to fame. Nope, never heard of it. Is it a rock worth living under?

I only heard about it this week. Then saw a former colleague post about it yesterday. Feels like its only just now breaking into mainstream tech awareness, I'm sure most of my colleagues haven't heard of it.
Post reply on HN