Claude, Codex, and Hermes installed unowned code inside corporate networks

| Source: Ars Technica AI

Tags: Claude, Codex, AI agents, supply chain security, llms.txt, Anthropic, OpenAI, Nous Research

Israeli researchers found 227 install commands in corporate llms.txt files pointing at unregistered packages; they registered some names, hosted beacon code, and within an hour received a phone-home from a Fortune 500 company — confirming AI coding agents Claude, Codex, and Hermes blindly executed the installs.

Details

Researchers at an unnamed Israeli startup scanned 6,214 live domains belonging to defense contractors, Fortune 500 companies, and major tech firms, examining their llms.txt and llms-full.txt files — the machine-readable site summaries designed to guide AI agents. Of the 8,265 such files found, 120 pointed to package names on PyPI, npm, and other registries that nobody owned. The researchers registered some of those unclaimed names and hosted beacon code to test whether AI agents would execute them. Within one hour of registering the first package name, their server received a phone-home from a Fortune 500 company. Dozens more followed over time. Process chain data revealed the culprits: AI coding agents including Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes had read the llms.txt files, treated installation instructions as authoritative, and executed them without verification. The attack vector mirrors classic software supply-chain squatting — registering package names that legitimate projects reference — but with AI agents as the accelerant. Agents can discover and execute these instructions autonomously across hundreds of codebases, expanding the attack surface far beyond what human developers would encounter. At least one misconfigured site was already pointing visitors to live malware. Anthropic, OpenAI, and Nous Research did not respond to requests for comment. 'The trust model is broken,' researcher Alon Hertz said. 'Agents treat vendor docs as ground truth and don't question them — and neither do the humans supervising them.'