ELSEIF
Your brief EB
505 stories from 214 feeds 1270 clusters Refreshed 14 minutes ago next pull 03:42

LANGUAGES Signal 147

Researchers demonstrate AI coding agents executing unregistered packages found in llms.txt files on corporate networks

Illustration only Photo by Bruno Martins on Unsplash

Researchers found that AI coding agents, including Claude and OpenAI's Codex, execute unregistered code packages referenced in llms.txt files, allowing attackers to trigger supply chain compromises on corporate networks.

WHY IT MATTERS

AI coding agents treat vendor documentation as ground truth and execute referenced packages without sufficient verification. This creates a supply-chain attack surface where malicious actors can register unclaimed domains and distribute code that runs inside corporate environments.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Researchers scanned 6,214 domains and found 120 llms.txt files pointing to unregistered code packages or domains.

02

By registering some of these unclaimed names, researchers received phone-home signals from Fortune 500 companies within an hour.

03

The executing agents included Claude, OpenAI’s Codex, and Nous Research’s Hermes, showing that multiple AI coding tools blindly execute unverified packages.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Schneier on Security AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks Open ↗