毒化技能文件差点复发
Poisoned Skill File Persistence
要点
- 对话里给出的下载命令先核对域名和安装包,切勿直接粘贴进终端。
- 重装前逐条审阅备份中的 skill、hook 和配置,伪装成文风指南的文件最危险。
- SKILL.md 已是可执行指令,加载即可静默拉马并窃取凭证。
- 助手不会核验链接,把模型输出一律当不可信输入处理。
原帖开头
Got hacked yesterday. The link came from inside Claude chat. I was installing a transcription app. Claude sent the download link, and I pasted the command into the terminal. It all looked legit. It wasn't though. It was a copycat site bundling malware. It ran instantly, tried …







