AI coding agents installed unowned packages on Fortune 500 networks

a computer screen with a bunch of code on it

A stealth startup in Israel just demonstrated a supply chain attack vector that hits AI coding agents directly, and the results are not reassuring.

What the Researchers Did

The team scanned 6,214 live domains belonging to defense contractors, Fortune 500 companies, and Big Tech firms. Across those domains they found 8,265 llms.txt and llms-full.txt files. Of those, 120 files on 120 separate sites pointed to code packages or domain names that were not registered.

The researchers registered a handful of those unclaimed names and hosted packages that caused any machine executing them to phone home. Within an hour, they received a beacon response from a Fortune 500 company. Over time, responses came in from additional Fortune 500 companies and from startups.

Which Agents Were Involved

The beacon recorded the chain of parent processes behind each install. The agents confirmed as involved include:

  • Claude (Anthropic)
  • Codex (OpenAI)
  • Hermes (Nous Research)

Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication.

The Operator Takeaway

If your team uses any AI coding agent on a machine with access to internal systems, the llms.txt files those agents read can silently direct them toward unowned or malicious packages. The agent executes first and asks questions never. This is not a hypothetical. It happened on corporate networks within an hour of the researchers setting the trap.

The minimum precaution: treat any AI agent that has write access or install permissions as an untrusted process running in a sandboxed environment. Review what it installs before it installs it.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo