I
Agentic Intelligence · Infomly

Your AI coding agent just installed code from a documentation file nobody owns. Fortune 500s already got hit.

AI-Assisted Content — Produced with AI assistance and human editorial review. Learn more
120 corporate websites have documentation files pointing at code packages nobody registered.

AI coding agents from Anthropic, OpenAI, and Nous Research installed that code inside Fortune 500 networks anyway.

Within one hour.

Researchers at an Israeli stealth startup scanned 6,214 domains belonging to defense contractors, Fortune 500 firms, and Big Tech. They found 8,265 llms.txt files — the AI equivalent of robots.txt — and flagged 120 of them pointing at unregistered package names or dead domains.

They registered one of those unclaimed names. Put a beacon on it. Within 60 minutes, a Fortune 500 company's AI agent executed the install and phoned home.

The process logs named the agents: Claude, Codex, Hermes. All running with shell permissions on company machines.

This is not a prompt injection. Nobody poisoned the model.

The llms.txt file was served over HTTPS on the company's own domain. The agent saw authoritative documentation. It ran pip install. No questions asked.

Endpoint detection didn't fire. To every EDR tool in the stack, this looked like a developer running a legitimate package manager with a sanctioned agent. The failure sits upstream — in the gap between what an agent reads and what it executes.

One site, clerk.com, was already weaponized. An attacker claimed an unregistered npm package referenced in the documentation and loaded it with live malware.

"The trust model is broken," researcher Alon Hertz told Ars Technica. "Agents treat vendor docs as ground truth. Neither the agents nor the humans supervising them question it."

Audit every llms.txt and llms-full.txt your company publishes. Verify every package name your AI agents are authorized to install. If a package in your documentation isn't registered to your namespace, register it today or remove the reference. Your EDR won't save you from this one.

SOURCE: https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
VERIFIED: Ars Technica (Dan Goodin, Aug 27), Gate News, AI Chat Daily, Startup Fortune
SIGNAL: AI coding agents are now a supply-chain attack vector. Every documentation file your company publishes is an execution surface. This changes how enterprises govern agentic AI access.
💬 Consultation · Got questions? Talk to an expert →
Enterprise AI Impact — filtered for signal, not noise The AI briefing CTOs read before their morning meeting 3 minutes. Zero fluff. Only what moves the needle. $5/mo — your cheapest competitive edge
Subscribe — $5/mo

0 Comments

No comments yet. Be the first.