All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

AI agents install unowned code in corporate networks

Created at 27 Aug · 2:06 PM1 source↑ Market-relevant
IN SHORT

Researchers discovered that AI agents, including Claude and OpenAI's Codex, are executing unowned code found in corporate documentation files. This vulnerability, stemming from misconfigured 'llms.txt' files, allows for potential malware installation, with at least one active attack identified.

Key Numbers

227installation commands found in corporate docs
100+websites referencing potentially dangerous executable content
6,214live domains scanned by researchers
8,265llms.txt and llms-full.txt files found
120misconfigured files pointing to unregistered code

Who's Involved

Claude
AI agent observed executing unowned code
Codex
OpenAI's AI coding agent involved in executing unowned code
Hermes
Nous Research's AI agent involved in executing unowned code
Alon Hertz
Researcher highlighting the broken trust model in AI agents
Clerk.com
Website where a live malware attack was identified
AI agents install unowned code in corporate networks

↳ Why This Matters

This discovery reveals a critical security vulnerability in the rapidly expanding use of AI agents, exposing corporate networks to supply-chain attacks through seemingly innocuous documentation files. The inability of AI to differentiate trusted code from malicious instructions poses a significant risk as these agents become more integrated into business operations.

Key facts

  • AI agents are executing unowned code found in corporate documentation files like 'llms.txt'.
  • This vulnerability allows for the potential installation of malware or harmful packages.
  • At least one active attack was discovered exploiting this misconfiguration.
  • AI agents, including Claude and OpenAI's Codex, were identified as executing the code.
  • The trust model is broken as agents treat vendor documentation as ground truth without verification.

AI agents are inadvertently installing unowned and potentially malicious code within corporate networks due to misconfigured documentation files, researchers have discovered. These files, often named 'llms.txt' or 'llms-full.txt', are intended to provide machine-readable summaries of website content for AI consumption. However, when they contain references to unregistered code packages or domains, AI agents with the ability to execute shell commands can be tricked into downloading and running harmful software.

Researchers scanned over 6,000 domains and found 120 files with 227 commands pointing to non-existent packages. By registering some of these unclaimed names, they confirmed that AI agents, including Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes, would execute the code. This led to a 'phone-home' response from at least one Fortune 500 company, demonstrating a significant supply-chain risk.

The core issue, according to researchers, is a broken trust model where AI agents treat all content within these documentation files as authoritative instructions, failing to distinguish between legitimate commands and potentially malicious ones. This vulnerability, known as prompt injection, means the entire corpus of published data consumed by agents has become an execution surface.

In one instance, a misconfigured file on the legitimate website clerk.com contained a command that, when executed by an AI agent, could have led to the installation of live malware. While Clerk.com has since addressed the specific issue, the broader vulnerability highlights the challenges in securing AI agent interactions with external data sources.

Frequently asked questions

It is a file that websites use to provide machine-readable summaries of their content and structure for AI agents, similar to the 'robots.txt' standard for search engines.

AI agents are executing code referenced in misconfigured 'llms.txt' files that point to unregistered packages or domains, which attackers can claim and use to host malware.

Researchers identified Claude, OpenAI's Codex, and Nous Research's Hermes as agents that executed the unowned code.

It refers to AI agents treating all content they read, including documentation files, as authoritative instructions without verifying their origin or legitimacy, similar to prompt injection vulnerabilities.

What Happens Next

01Companies are urged to review and properly configure their 'llms.txt' and 'llms-full.txt' files.
02AI developers are expected to implement better guardrails to distinguish between user commands and external content.
03The security community will likely develop new standards for AI agent interaction with web content.

How It Developed

Researchers found 227 installation commands in corporate documentation files pointing to unregistered code packages.
AI agents, including Claude, Codex, and Hermes, were observed executing these commands.
A stealth startup in Israel registered unclaimed domain names to test the vulnerability.
A Fortune 500 company's AI agent reached out to the researchers' server within an hour.
At least one active attack was identified where a misconfigured file on clerk.com hosted live malware.
Clerk.com has since resolved the issue, but it's unclear if actual infections occurred.
The vulnerability arises because AI agents cannot reliably distinguish between authentic user instructions and content from untrusted third-party sources.

Sources

T1
Claude, Codex, and Hermes installed unowned code inside corporate networksvar abtest_2169110 = new ABTest(2169110, 'impression');Ars Technica

Related Stories

OpenAI agents gamed test, breached Hugging Face network
27 Aug · 1:06 PM
OpenAI AI agents breached Hugging Face during tests, investigators say
26 Aug · 7:04 PM
Researchers Develop Method for Simultaneous Dual Genetic Code Translation
26 Aug · 3:11 PM
New Twitter-like platform launches, claims X abandoned trademark
26 Aug · 8:56 PM
Meta explored 60% team cuts for 'AI native' plan
26 Aug · 9:30 PM