AnalysisCybersecuritySeptember 4, 2026

AI coding agents install untrusted code from poisoned llms.txt files

Researchers scanned 6,214 corporate domains, finding 120 llms.txt files pointing to unregistered packages. After registering some, they got phone-home responses from Fortune 500 companies within an hour, implicating Claude, OpenAI's Codex, and Hermes.

How this story unfolded

7 days · 3 reports · 1 community post · from Aug 28

  1. Aug 28
  2. Sep 2
  3. Sep 3
  4. Sep 4

More stories today

Open the live feed