Subscribe free Search SF Aug 29, 2026 · 4:13 PM – Users OnlineOnline US| INTERNATIONAL| ASIA| SF Featured Subscribe✉ SF Startup Fortune Search ⌕ Home News AI Entrepreneur Interviews Guides Tech Opinion Crypto Latest Most Read A Paris Developer's Open Source Tool… A Mystery Model Called Ox Alpha… From Database to AI Data Platform:… Zondacrypto's Second CEO Has Vanished After… A Paris Developer's Open Source Tool… A Mystery Model Called Ox Alpha… From Database to AI Data Platform:… Zondacrypto's Second CEO Has Vanished After… Home › Ai Researcher Alon Hertz Tricked Claude, Codex and Hermes Into Running Malware Security researcher Alon Hertz found that llms.txt, the file over 100 companies publish to help AI agents read their sites, can smuggle malicious install commands straight into corporate networks. Claude, Codex and Hermes all ran his proof-of-concept code, and one vendor, Clerk, was tied to a real npx confusion incident that let an attacker's package masquerade as its own.

AI coding agents are reading corporate documentation as if it were trusted code. Alon Hertz's research shows why that habit can put unclaimed packages inside real company networks.

Alon Hertz didn't need a zero-day to get code executed inside corporate environments. According to Ars Technica, researchers at a stealth startup in Israel found that ordinary llms.txt and llms-full.txt files, the plain text files companies publish to help AI systems read their sites, can point coding agents toward packages nobody owns.

The numbers are uncomfortable. The researchers scanned 6,214 live domains tied to defense contractors, Fortune 500 companies and Big Tech firms. Across 8,265 llms.txt and llms-full.txt files, they found 120 files, each on a different site, that referenced unregistered package names or domains. Ars Technica reported that 227 install commands in corporate documentation pointed at code nobody owned. That is not a small typo class. It's a supply-chain opening.

The researchers registered a handful of the unclaimed names and hosted packages that would phone home when executed. Within an hour, a Fortune 500 company had triggered one of the callbacks. More followed from other large companies and startups. The process logs pointed to AI coding agents, including Anthropic's Claude, OpenAI's Codex and Nous Research's Hermes. Anthropic, OpenAI and Nous did not respond to Ars Technica before publication.

This article was aggregated automatically by CyberWire Daily's newsfeed engine. Original reporting: startupfortune.com.