Cybersecurity researchers discovered that AI agents can be tricked into installing malware by following outdated or unclaimed documentation links found on 120 major corporate websites.
Key Points
- Researcher Alon Hertz identified 8,265 llms.txt files across 6,214 domains belonging to Fortune 500 companies and defense contractors.
- 120 domains contained references to unregistered code packages or domains, creating a significant supply chain vulnerability.
- AI models including Claude, OpenAI’s Codex, and Nous Research’s Hermes were shown to execute commands from these potentially malicious documentation sources.
- Registering these unclaimed packages allowed researchers to successfully trigger pings from corporate systems in under one hour.
- Experts recommend that organizations audit their documentation for broken links and restrict AI agents from executing commands directly from web-based instructions.