Claude, Codex, and Hermes installed unowned code inside corporate networks

← Back to the feed

Claude, Codex, and Hermes installed unowned code inside corporate networks

Ars Technica · 5 hours ago

Researchers found that 120 machine-readable website documentation files on 100-plus corporate sites referenced unregistered software packages or domains, creating an opportunity for attackers to claim those names and distribute malicious code. The issue matters because coding agents may treat these files as trusted setup instructions and automatically run installation commands inside company networks, expanding software supply-chain risks.

The researchers scanned 6,214 domains associated with defence contractors, Fortune 500 firms and major technology companies, finding 8,265 llms.txt or llms-full.txt files. After registering several unclaimed names with harmless ‘phone-home’ proof-of-concept code, they received responses from dozens of organisations, including Fortune 500 companies, and traced some installations to Claude, OpenAI Codex and Hermes; they also found one Clerk-related command pointing to an npm package hosting active malware.

  • Unclaimed package names let attackers target AI-assisted corporate development environments.
  • Researchers observed proof-of-concept executions at dozens of companies.
  • One referenced npm package was found distributing live malware.

Software

Read the full article at the source →