AIToday
Large Language ModelsAI Safety & AlignmentArs Technica AIPublished: Aug 28, 2026, 01:00 JST1 min read

AI agents tricked into running unowned code in corporate networks

AI agents tricked into running unowned code in corporate networks

Key takeaway

  • A security firm found that AI coding agents can be tricked into installing unowned code from documentation files.

  • Over 100 websites link to such code.

  • Some Fortune 500 companies already executed proof-of-concept code.

3 Key Points

  1. What happened

    Documentation files on over 100 websites contain executable content that can be automatically installed when AI agents visit. Researchers found 120 such files across 8,265 llms.txt and llms-full.txt files on 6,214 domains belonging to defense contractors, Fortune 500s, and Big Tech.

  2. Why it matters

    Within an hour of registering unclaimed domains, researchers got a response from a Fortune 500 company, and a few dozen more over time. The phone-home beacons revealed coding agents including Claude, OpenAI's Codex, and Hermes were involved, showing that agents trust vendor docs as ground truth, which one researcher called a broken trust model.

  3. What to watch

    At least one misconfigured site is directing visitors, human or AI, to live malware. The supply-chain surface is expanding as agents spread across SaaS, cloud, and endpoints, and current guards don't cover it, per the researchers.

Ask the AI about this article →

Context & Analysis

The discovery highlights a new attack vector in the AI supply chain. llms.txt files are the AI equivalent of robots.txt, meant to help agents understand website content. However, attackers can register unclaimed domains to serve malicious code when agents fetch these files. The researchers' test showed real-world impact within an hour, with a Fortune 500 company reaching out. This indicates that current security measures don't account for agents' tendency to execute code without verification. As agentic AI spreads across corporate layers, the risk of such attacks may grow. The lack of response from major AI vendors suggests the issue remains unresolved.

FAQ

How did the researchers test the risk?
They scanned 6,214 live domains and found 120 files linking to unregistered code packages or domains. They registered some of those names and hosted packages that made any executing machine contact their server.
Which AI agents were involved?
The phone-home beacons recorded that Claude, OpenAI's Codex, and Nous Research's Hermes were among the coding agents that executed the code.
Ars Technica AIRead Original Article

Get the latest Large Language Models news every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleHugging Face rolls out $399 rollerskating robot duck