Technology
AI agents execute unowned code found in machine-readable website files
Researchers discovered that files intended to summarize site content for LLMs point to unregistered domains, allowing code execution within corporate networks.
The short version
- Security researchers found that 120 'llms.txt' and 'llms-full.txt' files on live website domains pointed to unregistered code packages or domains.
- By registering some of these unclaimed names, researchers triggered automatic installations and received 'phone-home' connections from dozens of companies, including Fortune 500 firms.
- Process tracing revealed that AI coding agents, including Claude, OpenAI's Codex, and Nous Research's Hermes, executed the unowned code.
Key facts
- Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to Big Tech firms, defense contractors, and Fortune 500 companies.[Ars Technica]
- Out of 8,265 scanned llms.txt and llms-full.txt files, 120 of them pointed to unregistered code packages or domain names.[Ars Technica]
- The llms.txt and llms-full.txt files are an emerging standard used by websites to offer machine-readable summaries for AI agents.[Ars Technica]
- After researchers registered a few of the unclaimed domains and hosted beacon packages, a Fortune 500 company sent a phone-home response within an hour, followed by dozens of other startups and Fortune 500 firms over time.[Ars Technica]
- Parent process tracing indicated that coding agents such as Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes were involved in executing the packages.[Ars Technica]
- Anthropic, OpenAI, and Nous Research did not respond to requests for comment prior to publication.[Ars Technica]
What remains uncertain
- At least one misconfigured site was noted to be directing visitors to live malware, though the specific identity of the site remains unspecified.[Ars Technica]