Security researchers found that llms.txt and llms-full.txt files on more than 100 websites referenced unregistered code packages, which AI agents automatically fetched and executed. After registering a handful of those unclaimed names, the researchers received callbacks from dozens of organizations, including Fortune 500 companies.
The callbacks revealed that Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes were among the agents that ran the code. At least one misconfigured site was also found directing both human and AI visitors to live malware.
Comments