logo

AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

ID: c2fc3ea9-078a-54d2-a212-b9ec3c063bb5

STIX ID: report--c2fc3ea9-078a-54d2-a212-b9ec3c063bb5

Feed Name: Schneier on Security

Threat Score
80/100

Date Published: 2026-09-04

Date Updated: 2026-09-10

Author: Bruce Schneier

...
...

Researchers scanned thousands of corporate domains and found llms.txt files pointing to unregistered code packages; after registering some of those names and hosting benign packages, they observed AI coding agents (Claude, OpenAI’s Codex, Nous Research’s Hermes) cause corporate systems to fetch/execute the packages and phone home, demonstrating that agent-driven untrusted code pulls create a supply-chain-style risk across Fortune 500 and startup networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.