Researchers scanned 6,214 corporate domains and found 120 llms.txt files pointing at code packages nobody registered.
Within an hour of claiming one package, a Fortune 500 company's AI agent installed it. No alerts. No blocks. No human in the loop.
Claude, Codex, and Hermes all executed the proof-of-concept. The agents treated vendor documentation as ground truth and ran the install commands without verification.
The trust model is broken. An llms.txt file served over HTTPS on an official domain is indistinguishable from legitimate setup instructions to an AI agent. Your EDR won't catch it because pip install from pypi.org looks like a developer running a permitted tool.
At least one site is already serving live malware through this vector. Clerk.com's documentation pointed to an unclaimed npm package. Someone claimed it and planted malware. Clerk has since fixed it. The pattern remains.
The researchers found 227 install commands in corporate documentation pointing at code nobody owns. Defense contractors, Fortune 500s, Big Tech — all affected.
Audit every llms.txt and llms-full.txt file on your domains today. If your AI agents have shell access, they are already reading these files. The line between data and executable code just collapsed. Your security controls were built for a world where documentation didn't execute itself. That world is gone.
Your AI coding agent just installed code from a documentation file nobody owns. Fortune 500s already got hit.
AI-Assisted Content — Produced with AI assistance and human editorial review.
Learn more
0 Comments