An encrypted developer recently disclosed that while building a working environment, he obtained a downloading address for a transfer application via Claude, and the result was placed in a counterfeit official network. After the software was downloaded, the equipment was quietly implanted into the information theft program, including the password, the exchange account voucher and the hot wallet private key.

We'll reload and re-infect.

Upon detection of the anomaly, the developer isolated the equipment and fully reassembled the working computer. It would appear that the risk has been cleared, but when the backup file was restored, he found that an AI profile called SKILL.md had been moved.

This document was originally used as a personal AI style guide. The attackers modified the document structure to enable them to automatically connect to the attacker ' s server after being imported into the new clean equipment, download the information steal program again and continue to collect vouchers.

Hide behind door into profile

This means that the risk comes not only from the malware originally downloaded, but also from trusted configuration documents during subsequent recovery. Even if the operating system has been re-assessed, as long as contaminated documents are reused, malicious procedures may return to the equipment.

It was reported that the incident revealed a new pattern of attack: hackers not only falsify download links provided by AI, but also hide the back door into AI skills or configuration files to form a continuous infection path.

Web3 Developer Focus

Illia Polosukhin, a co-founder of NEAR Protocol, is also concerned. He cautioned that the security issues surrounding the autonomous AI proxy infrastructure were becoming more prominent and that there had been an increase in the number of attacks using “text poisoning”.

For Web3 developers, local work equipment has been a high-value target, as it tends to preserve the development environment, account vouchers and wallet keys. This incident shows that the.md or.json seemingly common AI profile can no longer be simply considered harmless text.

In the future, such files will need to be checked as if they were to be processed as enforceable codes before being imported, synchronized or restored. Otherwise, the attackers may take back the malware with the new equipment by using the AI tools and configurations in the daily workflow.