Hackers Hijack AI Skill Files to Reinfect Computers
A Web3 project co-founder nearly lost control of his digital assets after following recommendations from an artificial intelligence assistant. The incident revealed a new cyberattack vector in which hackers inject hidden backdoors into AI skill configuration files, allowing them to reinfect computers even after a complete operating system reinstall.
The attack began when the developer set up his work environment and asked Claude for a link to download a transcription app. The AI assistant provided an address that led to a phishing clone of the program's official website.
After the software was downloaded, an infostealer was silently installed on the developer's work laptop, malware designed to steal passwords, exchange credentials, and private keys from hot wallets.
The developer detected the compromise in time, isolated the device, and completely reinstalled the operating system. However, the threat was not eliminated.
While attempting to restore files from a backup, Lunah discovered changes to a SKILL.md document that he used as a personal style guide for AI. The hackers had managed to modify the structure of the text file.