📣 Send us your press release
Site updates every 15 minutes
Technology

Ars Technica: AI Agents Installed Unowned Code Inside Corporate Networks

Researchers discovered that over 100 websites contained potentially dangerous executable content installed automatically by AI agents, including Claude and Codex. At least a dozen companies, some Fortune 500s, executed this proof-of-concept code.

27 August 2026
Ars Technica: AI Agents Installed Unowned Code Inside Corporate Networks

Ars Technica reports on a vulnerability where websites inadvertently cause AI agents to install unowned executable code within corporate networks. Over 100 websites were found to reference potentially dangerous content that executed when accessed by various AI agents.

The issue stems from llms.txt and llms-full.txt files, which websites use to provide machine-readable content summaries for AI. Researchers scanned thousands of domains and identified 120 files on different sites pointing to unregistered code packages or domains. By registering these unclaimed names and hosting packages, researchers tested the vulnerability.

Upon visiting these sites with AI agents, the researchers received "phone-home" responses from corporate networks, confirming execution. Over a dozen companies, including Fortune 500 corporations, were confirmed to have executed the proof-of-concept code, with one response received within an hour.

The AI agents identified as responsible for executing the code include Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes. The companies behind these AI agents have not commented on the incident at the time of publication. Additionally, at least one misconfigured site was found to be directing all visitors, human or AI, to live malware.

Original source: arstechnica.com