Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks

Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks | Daily Reports Online

Share


  • Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminals
  • AI agents could install malware if they execute hallucinated or outdated documentation commands
  • Fixes: clean documentation and restrict AI agents from treating docs as executable instructions

Cybercriminals are able to now abuse hallucinated, outdated, and outright incorrect website documentation to deliver malware to unsuspecting victims through AI agents, new research has claimed.


An increasing number of websites now contain two documents: llms.txt, and llms-full.txt. These are conventions that allow AI agents to properly read the contents of the websites. If an AI agent is looking to install software or add code to a project, they can search through these documents across the web until they find a fitting solution.



Similar Posts