227 install commands were found in corporate docs pointing at code nobody owns. Claude, Codex, and Hermes installed unowned code inside corporate networks. Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents.
A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware. The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable summaries of the siteโs content and its high-level structure.
These files are the AI equivalent of the robots.txt standard that instructs search engines how to index the siteโs content. Google Lighthouse, a tool for helping web developers, has more here. Correctly configured llms.txt and llms-full.txt files for Cloudflare are here and here.
How the researchers found it Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies.
Discover more from ChuckysCarnage
Subscribe to get the latest posts sent to your email.
