Schneier on Security
Follow
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
AI coding agents currently pose a trustworthiness concern. Researchers identified 120 unregistered code packages or domain names across 6,214 live domains belonging to major companies. These findings were within llms.txt and llms-full.txt files. To test the risk, they registered some of these unclaimed names and hosted malicious packages. When AI agents processed these files, they would "phone home" to the researchers' server. Within an hour, a Fortune 500 company's machine contacted the researchers. Over time, several dozen more responses came from other Fortune 500 companies and startups. The researchers' beacon revealed that coding agents like Claude, OpenAI's Codex, and Nous Research's Hermes were involved in these installations. This demonstrates how AI agents can interact with potentially malicious, unregistered code. The incident highlights a significant security vulnerability. The involved AI companies did not comment.