Coding agents ran attacker code via llms.txt
Archive item — written before sources were shown.
Researchers registered fake packages named in real llms.txt files and got Claude, Codex, and Hermes to install and run them inside Fortune 500s.
Researchers at an Israeli security startup scanned 6,214 live domains belonging to defense contractors, Fortune 500 companies, and Big Tech firms for llms.txt and llms-full.txt files, the emerging convention companies use to give AI agents a machine-readable map of their site. Of 8,265 such files found, 120 pointed to code packages or domains that were never actually registered. The researchers claimed a handful of those unclaimed names and hosted harmless beacon packages in their place. The first callback arrived in under four minutes, from inside a company worth several hundred billion dollars; dozens more followed from other Fortune 500s and startups within the hour.
The beacon’s logging showed which software had executed the install commands: coding agents including Claude, OpenAI’s Codex, and Nous Research’s Hermes. In one case, on Clerk’s own documentation site, the researchers found the unclaimed slot had already been claimed by someone else and was hosting live malware, not a research beacon, meaning at least one active attack was already exploiting the gap before the researchers got there. Clerk has since fixed the file.
Why agents fell for it
An llms.txt file sits on the company’s own domain, served over HTTPS, in a format built specifically for AI consumption, so an agent has no obvious reason to doubt it. Researcher Alon Hertz put it plainly: “the trust model is broken. Agents treat vendor docs as ground truth and don’t question them, and neither do the humans supervising them.” Many of the broken entries predate the AI era, carried over from old human-written docs, which means this is not a new kind of file, just a new kind of reader willing to execute what it finds. It is the same underlying weakness behind the recent OpenAI-agent breach of Hugging Face and other agentic prompt-injection research: anything an agent reads is a potential instruction, and endpoint security tools see nothing unusual because the agent is running an approved package manager exactly as designed.
- 01Data Became Code: We Ran Code Inside Fortune 500s Using Files They Published for AI Agentsmedium.com · primary research
- 02Claude, Codex, and Hermes installed unowned code inside corporate networksarstechnica.com · independent reporting
