AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
ID: c2fc3ea9-078a-54d2-a212-b9ec3c063bb5
STIX ID: report--c2fc3ea9-078a-54d2-a212-b9ec3c063bb5
Feed Name: Schneier on Security
Threat Score
Researchers scanned thousands of corporate domains and found llms.txt files pointing to unregistered code packages; after registering some of those names and hosting benign packages, they observed AI coding agents (Claude, OpenAI’s Codex, Nous Research’s Hermes) cause corporate systems to fetch/execute the packages and phone home, demonstrating that agent-driven untrusted code pulls create a supply-chain-style risk across Fortune 500 and startup networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
