AI Coding Agents Installed Unowned Code Inside Corporate Networks via llms.txt Trust Flaws
Researchers at a stealth Israeli startup scanned 8,265 llms.txt and llms-full.txt files across 6,214 domains belonging to defence contractors, Fortune 500 and Big Tech companies, finding 120 files pointing to code packages or domains that were not registered โ 227 install commands in corporate documentation reference code nobody owns. After registering a handful of the unclaimed names and hosting beacon packages, the researchers received a phone-home response from a Fortune 500 company within an hour, and a few dozen more over time.
Beacon data showed Claude, OpenAI's Codex and Nous Research's Hermes coding agents executed the installs, and at least one misconfigured site was directing visitors to live malware. The research extends the week's agentic-AI theme: agents treat vendor documentation as ground truth, and abandoned package or domain names create a supply-chain surface no current guard covers. The findings were reported by Ars Technica and are not yet independently verified.