Claude, Codex, and Hermes installed unowned code inside corporate networks
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
Critical security finding about AI agents installing unowned code in corporate networks, directly relevant to AI/ML ops and supply chain security.
Researchers found 120 llms.txt and llms-full.txt files on 6,214 scanned domains pointing to unregistered code packages or domains. When they registered a few and hosted proof-of-concept packages, coding agents including Claude, OpenAI's Codex, and Nous Research's Hermes automatically executed them inside Fortune 500 and startup networks within an hour. One live exploit on clerk.com uses an `npx` command to fetch and execute a malicious binary without adding it to the dependency manifest, demonstrating a real supply-chain attack vector targeting AI agents.
Dan Goodin — Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. A journalist with more than 25 years experience, he has been chronicling the...