Claude, Codex, and Hermes installed unowned code inside corporate networks
ID: 532a9f22-db93-50dd-8e3d-847c38f71b64
STIX ID: report--532a9f22-db93-50dd-8e3d-847c38f71b64
Feed Name: Ars Technica Security (category)
Threat Score
Researchers found that llms.txt and llms-full.txt files on over 100 websites referenced code packages or domains that could cause AI agents to automatically install or execute content; by registering unclaimed names the researchers observed phone-home callbacks from several Fortune 500s and other companies, and at least one misconfigured site pointed to live malware, highlighting a supply-chain/trust vulnerability in agentic AI usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
