AI Agents Installed Malware From Corporate Docs

AI Agents Installed Malware From Corporate Docs
Researchers scanned over 6,000 corporate domains and found 120 sites with llms.txt files referencing unregistered code packages. By claiming those vacant package names and hosting beacon code, they triggered automatic installs from dozens of companies, including Fortune 500 firms, within hours. Coding agents Claude, Codex, and Hermes were identified in the process chains. At least one active attack was already exploiting the flaw, with a malicious package planted at a name referenced in Clerk's documentation. The vulnerability stems from AI agents treating vendor documentation as trusted instructions, executing shell commands without verifying package ownership or authenticity.
Read the original article →