# What happened Researchers at a stealth Israeli startup scanned 6,214 live domains belonging to defense contractors, Fortune 500 companies, and Big Tech. They cataloged 8,265 files named llms.txt or llms-full.txt. Of those, 120 files (each on a different site) referenced one or more code packages or domain names that were not registered.
# How the test was run
# What they observed
The researchers captured the chain of parent processes that initiated the installs. That evidence implicated several AI coding agents in the activity, specifically Claude, OpenAI's Codex, and Nous Research's Hermes. Anthropic, OpenAI, and Nous Research had not responded to requests for comment by the time of publication.
# Why this matters The finding highlights a practical attack surface created when documentation or vendor instruction files point to external packages or domains. The files themselves can be benign and originally published by legitimate vendors. If a referenced package or domain is later abandoned and someone else claims it, an agent or automated process that treats the vendor file as authoritative may fetch and execute new, potentially malicious code.
Researcher Alon Hertz summarized the problem as a broken trust model: agents accept vendor documentation as ground truth and act on it without sufficient questioning. As agents gain privileges and spread across SaaS, cloud, and endpoints, the number of potential supply-chain entry points increases.
# Relation to known supply-chain threats The article frames this exposure as directly relevant to supply-chain-style attacks—situations where an attacker gains access by compromising something the target already trusts. The documented behavior resembles supply-chain compromise patterns because it leverages preexisting trust relationships (vendor documents pointing to packages) rather than direct exploitation of a perimeter.
# What the coverage shows, directly
- Vendors' public files can contain references to external code that become dangerous if ownership of the referenced domain or package changes.
- AI coding agents are already operating with enough autonomy and connectivity that they can cause candidate code to be fetched and executed on corporate machines.
- At least in the researchers' test, real corporate infrastructure contacted their hosted packages after the names were registered.
# Takeaway The scan and test demonstrate a concrete mechanism by which abandoned package names or domains referenced in vendor documentation can be weaponized once claimed by a third party. The result is a widened supply-chain attack surface driven by agentic behavior that treats external references as executable instructions.
# Quotable observation "Agents treat vendor docs as ground truth and don't question them—and neither do the humans supervising them," researcher Alon Hertz said in an interview cited by the report.