DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

AI Agents Install Unowned Packages via Poisoned llms.txt Files

Forensic Summary

Researchers discovered that over 120 corporate websites contained misconfigured llms.txt files referencing unregistered package names, which AI coding agents including Claude, Codex, and Hermes automatically executed as trusted installation instructions. By registering a handful of the unclaimed package names and hosting beacon payloads, researchers received phone-home responses from dozens of companies including Fortune 500 firms within hours, confirming real-world agent-driven supply chain compromise. The attack exploits the implicit trust AI agents place in vendor documentation files, with at least one site found directing visitors to live malware.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/ai-agents-install-unowned-packages-via-poisoned-llms-txt-files/

Top comments (0)