Claude, Codex, and Hermes installed unowned code inside corporate networks
Highlights a critical, novel security vulnerability in the AI supply chain that developers and security engineers must understand and mitigate.
AI Summary
Researchers discovered misconfigured AI instruction files (llms.txt) on over 100 corporate sites can trick AI coding agents like Claude and Codex into automatically executing unregistered, potentially malicious code.
Excerpt
227 install commands were found in corporate docs pointing at code nobody owns.
