Claude served a malware link, then a poisoned skill file kept it alive
Newsroom / Security and Privacy desk
An AI assistant handed its user a malware link. That turned out to be the less alarming half of the story.
What happened
X user Numa was installing a transcription app on August 27. Claude served the download link in chat, she pasted the command into her terminal, and everything looked legitimate. The link led to a copycat site bundling malware, which ran instantly and tried to take everything it could. Nothing sensitive got out, so she wiped the laptop and rebuilt it clean.
The part that pushed her post past 912,000 views came during recovery. Restoring from her backup, she found a poisoned SKILL.md file for Claude Code. It looked exactly like her own writing style guide, but buried inside were instructions to silently re-download the malware and steal her credentials every time the AI loaded the file. Restoring that one file would have compromised the new laptop on day one. What saved her was habit: she reads every skill, hook and config file before letting the AI touch them.
Why this attack class matters
Her own conclusions were precise. AI assistants will hand you links they never verified, so check before you paste. And AI agent configuration files are executable code now, disguised as notes, so they have to be read like code. A recent review of a popular Claude Code skills marketplace found roughly a quarter of shared skills carrying vulnerabilities, which suggests this is a pattern, not an isolated case.
The attack works because agent configs sit in a blind spot: they look like documentation, get restored from backups without scrutiny, and are consumed by a system that follows instructions written in plain English. Treating them as part of the attack surface is now simply part of using AI tools.
Sources
ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.