Security researchers found that AI agents crawling websites could be directed to install unclaimed code through links in llms.txt and llms-full.txt files. After scanning more than 6,000 corporate domains, the researchers identified 120 sites referencing unregistered packages and registered some of those packages to track execution.
Within an hour, a Fortune 500 company ran the proof-of-concept code, and dozens of other companies followed, with telemetry revealing Claude, OpenAI Codex, and Nous Research Hermes as the responsible agents. At least one misconfigured site was already steering visitors, both human and AI, toward live malware.
Comments