Schneier iconSchneierSep 4, 2026 ~8 min source read

Researchers Found AI Coding Agents Installing Unclaimed Code Referenced in Vendor Files

A scan of thousands of corporate domains uncovered vendor files pointing to unregistered packages. When researchers claimed those names and served simple beacons, live corporate machines reached back—sometimes via AI coding agents—exposing a new supply-chain risk.

Share this story

Send the public story page.

Useful takeaways from this story.

AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks.

"The trust model is broken," Alon Hertz, one of the researchers, wrote in an interview.

Also pointing out the "directing mind" and "arms length deniability" issues AI systems will give authoritarians and political actors.

# What happened Researchers at a stealth Israeli startup scanned 6,214 live domains belonging to defense contractors, Fortune 500 companies, and Big Tech. They cataloged 8,265 files named llms.txt or llms-full.txt. Of those, 120 files (each on a different site) referenced one or more code packages or domain names that were not registered.

# How the test was run

# What they observed

The researchers captured the chain of parent processes that initiated the installs. That evidence implicated several AI coding agents in the activity, specifically Claude, OpenAI's Codex, and Nous Research's Hermes. Anthropic, OpenAI, and Nous Research had not responded to requests for comment by the time of publication.

# Why this matters The finding highlights a practical attack surface created when documentation or vendor instruction files point to external packages or domains. The files themselves can be benign and originally published by legitimate vendors. If a referenced package or domain is later abandoned and someone else claims it, an agent or automated process that treats the vendor file as authoritative may fetch and execute new, potentially malicious code.

Researcher Alon Hertz summarized the problem as a broken trust model: agents accept vendor documentation as ground truth and act on it without sufficient questioning. As agents gain privileges and spread across SaaS, cloud, and endpoints, the number of potential supply-chain entry points increases.

# Relation to known supply-chain threats The article frames this exposure as directly relevant to supply-chain-style attacks—situations where an attacker gains access by compromising something the target already trusts. The documented behavior resembles supply-chain compromise patterns because it leverages preexisting trust relationships (vendor documents pointing to packages) rather than direct exploitation of a perimeter.

# What the coverage shows, directly

  • Vendors' public files can contain references to external code that become dangerous if ownership of the referenced domain or package changes.
  • AI coding agents are already operating with enough autonomy and connectivity that they can cause candidate code to be fetched and executed on corporate machines.
  • At least in the researchers' test, real corporate infrastructure contacted their hosted packages after the names were registered.

# Takeaway The scan and test demonstrate a concrete mechanism by which abandoned package names or domains referenced in vendor documentation can be weaponized once claimed by a third party. The result is a widened supply-chain attack surface driven by agentic behavior that treats external references as executable instructions.

# Quotable observation "Agents treat vendor docs as ground truth and don't question them—and neither do the humans supervising them," researcher Alon Hertz said in an interview cited by the report.

More context around this story.

Your Agent Trusts Things You Never Approved
Cisco iconCiscoSep 3, 2026

Your Agent Trusts Things You Never Approved

Several notable breach retrospectives of the last decade have the same shape. The attacker didn't break down the front door. They compromised something the target had already decided to trust — a package, a build tool, a base image — and walked in..

Schneier iconSchneierSep 2, 2026

AI Agents Are Now Emailing Me with Their Security Concerns

I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app