Claude, Codex, and Hermes installed unowned code inside corporate networks
Researchers found 120 site files pointing AI coding agents to unregistered packages, and a Fortune 500 company phoned home within an hour.
5 Articles
5 Articles
Claude, Codex, and Hermes installed unowned code inside corporate networks
Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware. The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging conven…
IA agents like Claude and Codex suffer from a major vulnerability that threatens the safety of companies. This problem comes from configuration files for machines, called "llms.txt", which sometimes contain references to non-existent software or expired domains. Researchers have shown that attackers can register these vacant names to induce AIs to automatically install viruses within business networks. This flaw highlights the fact that the IA a…
Coverage Details
Bias Distribution
- 50% of the sources lean Left, 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium








