TECHNOLOGY · VERIFIED DEVELOPMENT
AI Agents Install Unowned Code Inside Corporate Networks
WHY IT MATTERS
This vulnerability highlights the risk of AI agents installing malicious code inside corporate networks, potentially compromising sensitive information and disrupting business operations.
What happened
Researchers at a stealth startup in Israel discovered that over 100 websites, including those of Fortune 500 companies, contain potentially dangerous executable content in llms. txt and llms-full.
txt files. These files, used for machine-readable summaries, are being referenced by AI agents such as Claude, Codex, and Hermes, leading to automatic code installation.
The researchers found that some sites are directing visitors to live malware, and they have received responses from a few dozen companies, including Fortune 500s, after registering unclaimed domain names.
PRIMARY SOURCES
Claude, Codex, and Hermes installed unowned code inside corporate networks
Ars Technica · Dan Goodin · Discovery only; Condé Nast copyright terms apply