I have a hard time believing that Claude instantly figured out this was malware...
I've fed it obfuscated JavaScript before, and it couldn't figure it out... and then there was the time I tried to teach it nftables... whooo boy...
Except in this case the code wasn't obfuscated, right?
I think the usual response to that is "have you tried again recently?"