The Actual News

Neutral summaries of your favorite news sources — just the facts.

Claude, Codex, and Hermes installed unowned code inside corporate networks

Claude, Codex, and Hermes installed unowned code inside corporate networks

Summary

Researchers found that many websites, including some of big companies, have special files called llms.txt that tell AI programs how to use code from their sites. Some of these files list fake or unclaimed software packages and addresses. When AI tools download and run these packages without checking, they might install harmful software.

Key Facts

  • More than 100 websites have files that list potentially unsafe code for AI agents to use automatically.
  • Researchers scanned over 6,000 websites from defense contractors, Fortune 500 companies, and Big Tech firms.
  • They found 120 sites with files pointing to unregistered software packages or fake web addresses.
  • By registering some unclaimed packages, researchers saw that AI coding tools like Claude, Codex, and Hermes tried to download and run code from these packages.
  • Some AI systems run commands directly based on these files, creating a security risk if the packages are malicious.
  • The files are similar to robots.txt files but designed to guide AI agents on how to interact with websites.
  • At least one real live malware attack is already using this method.
  • AI companies mentioned in the research had not responded for comment by the time of publication.
Read the Full Article

This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.

Save articles & personalize your feed — Create a free account