Researchers found that AI coding agents like Claude, Codex, and Hermes executed unowned code within corporate networks by following installation commands listed in misconfigured llms.txt files on public websites. These files, intended to guide AI agents, included references to non-existent software packages and domains that attackers could claim to deliver malware, demonstrated by proof-of-concept tests showing real Fortune 500 companies inadvertently ran such code. The findings reveal a critical security gap where AI agents treat third-party documentation as authoritative without verifying it, enabling supply-chain risks and undermining traditional boundaries between data and executable code.
Claude, Codex, and Hermes Installed Unowned Code Inside Corporate Networks

