💻
💻 Technology

AI agents silently installed unowned code in corporate networks via llms.txt files

Researchers discovered that over 100 websites contain dangerous executable content inside llms.txt and llms-full.txt files — a convention used to give AI agents machine-readable site summaries. AI agents including Claude, Codex and Hermes automatically ran this code when visiting the sites, with several dozen companies, including Fortune 500 firms, unknowingly executing proof-of-concept payloads. At least one misconfigured site was directing visitors directly to live malware.

Comments

No comments yet