Claude Code踩坑约 2 分钟

毒化技能文件差点复发

Poisoned Skill File Persistence

要点

  1. 对话里给出的下载命令先核对域名和安装包,切勿直接粘贴进终端。
  2. 重装前逐条审阅备份中的 skill、hook 和配置,伪装成文风指南的文件最危险。
  3. SKILL.md 已是可执行指令,加载即可静默拉马并窃取凭证。
  4. 助手不会核验链接,把模型输出一律当不可信输入处理。

原帖开头

Got hacked yesterday. The link came from inside Claude chat. I was installing a transcription app. Claude sent the download link, and I pasted the command into the terminal. It all looked legit. It wasn't though. It was a copycat site bundling malware. It ran instantly, tried