Researchers found that llms.txt and llms-full.txt files on more than 100 sites pointed to unregistered code packages or domains, with at least one site serving live malware. After registering some of the unclaimed names, the researchers received connections from dozens of organizations, including Fortune 500 companies, within an hour.
Process logs showed that coding agents such as Claude, OpenAI's Codex, and Nous Research's Hermes had executed the proof-of-concept code inside corporate networks. The findings highlight how AI agents can be steered by machine-readable website instructions into installing unverified code.
Comments