{"id":71705,"date":"2026-08-31T06:37:17","date_gmt":"2026-08-31T06:37:17","guid":{"rendered":"https:\/\/www.europesays.com\/france\/71705\/"},"modified":"2026-08-31T06:37:17","modified_gmt":"2026-08-31T06:37:17","slug":"top-ai-tools-including-claude-codex-and-hermes-installed-suspicious-code-inside-corporate-networks","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/france\/71705\/","title":{"rendered":"Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks"},"content":{"rendered":"<p>Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminalsAI agents could install malware if they execute hallucinated or outdated documentation commandsFixes: clean documentation and restrict AI agents from treating docs as executable instructions<\/p>\n<p id=\"elk-9a0f2110-a2d5-11f1-9b92-018f3eff624b\">Cybercriminals are able to now abuse hallucinated, outdated, and outright incorrect website documentation to deliver malware to unsuspecting victims through <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/best\/best-ai-tools\" target=\"_blank\" data-url=\"https:\/\/www.techradar.com\/best\/best-ai-tools\" data-hl-processed=\"none\" data-article-category=\"pro\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/best\/best-ai-tools\" rel=\"nofollow noopener\">AI agents<\/a>, new research has claimed.<\/p>\n<p>An increasing number of websites now contain two documents: llms.txt, and llms-full.txt. These are conventions that allow AI agents to properly read the contents of the websites. If an AI agent is looking to install software or add code to a project, they can search through these documents across the web until they find a fitting solution.<\/p>\n<p><a id=\"elk-seasonal\"\/><\/p>\n<p id=\"elk-9a0f2110-a2d5-11f1-9b92-018f3eff624b-2\">Researchers have analyzed 6,214 live domains belonging to defense contractors, Fortune 500 organizations, as well as big tech. On these domains they found 8,265 of these .txt files and among them 120 (all on a different site) pointing to one or more code packages and domain names that weren\u2019t registered at all.<\/p>\n<p>Latest Videos FromTechRadar<\/p>\n<p><a id=\"elk-9a0f2188-a2d5-11f1-a022-c9938cbba032\"\/>Claiming packages and domains<\/p>\n<p id=\"elk-9a0f21f6-a2d5-11f1-9c19-937336e0c2dd\">There can be a myriad of reasons why they\u2019re not registered. It can be due to human error, renamed or abandoned packages, copy\/paste errors, or hallucinated documentation.<\/p>\n<p>Now, for the purpose of the experiment, the researchers registered some of these unclaimed names and hosted packages that would phone home when installed. It took less than an hour for a Fortune 500 company to start pinging, and the numbers soon grew to \u201ca few dozen more\u201d.<\/p>\n<p>            You may like<\/p>\n<p>This means that if the researchers can do it, so can cybercriminals. In theory, a cybercriminal could find these unclaimed packages and register <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/best\/best-malware-removal\" target=\"_blank\" data-url=\"https:\/\/www.techradar.com\/best\/best-malware-removal\" data-hl-processed=\"none\" data-article-category=\"pro\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/best\/best-malware-removal\" rel=\"nofollow noopener\">malware<\/a>. If an AI agent has permission to execute shell\/package-manager commands and stumbles upon this documentation, it can end up infecting the device.<\/p>\n<p>Claude, OpenAI\u2019s Codex, and Nous Research\u2019s Hermes were all \u201cguilty\u201d, the researchers said.<\/p>\n<p class=\"newsletter-form__strapline\">Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!<\/p>\n<p>To fix the vulnerability, two things need to happen. First, companies need to clean up their documentation and make sure it\u2019s not pointing towards non-existent or malicious content. Second, AI agents need to stop treating documentation as executable instructions. Since the latter most likely isn\u2019t happening any time soon, the immediate answer would probably lie in the former. In the meantime, organizations using AI for coding should consider the risks when granting AI agents permission to execute commands.<\/p>\n<p>Via <a data-analytics-id=\"inline-link\" href=\"https:\/\/arstechnica.com\/security\/2026\/08\/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks\/\" target=\"_blank\" data-url=\"https:\/\/arstechnica.com\/security\/2026\/08\/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks\/\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-article-category=\"pro\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">Ars Technica<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/france\/wp-content\/uploads\/2026\/08\/HpHXmtXFPnuzaQ8m9xNW8j.png\" alt=\"Best antivirus software header\"  loading=\"lazy\" data-new-v2-image=\"true\" data-original-mos=\"https:\/\/www.europesays.com\/france\/wp-content\/uploads\/2026\/08\/HpHXmtXFPnuzaQ8m9xNW8j.png\" data-pin-media=\"https:\/\/www.europesays.com\/france\/wp-content\/uploads\/2026\/08\/HpHXmtXFPnuzaQ8m9xNW8j.png\" class=\"rounded-[var(--image--border-radius,0)] person__avatar\" data-pin-nopin=\"true\" data-normal=\"https:\/\/www.europesays.com\/france\/wp-content\/uploads\/2026\/08\/HpHXmtXFPnuzaQ8m9xNW8j.png\"\/><\/p>\n<p>\nThe best antivirus for all budgets\n<\/p>\n<p>Our top picks, based on real-world testing and comparisons<\/p>\n<p><a href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJsWTJoeVlXUmhjaTVqYjIwb0FBUAE?hl=en-GB&amp;gl=GB&amp;ceid=GB%3Aen\" target=\"_blank\" id=\"elk-9a0f23cc-a2d5-11f1-8fca-5da6ad54816f\" data-url=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJsWTJoeVlXUmhjaTVqYjIwb0FBUAE?hl=en-GB&amp;gl=GB&amp;ceid=GB%3Aen\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-article-category=\"pro\" rel=\"nofollow noopener\"><\/p>\n<p class=\"vanilla-image-block\" style=\"padding-top:31.51%;\">\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/france\/wp-content\/uploads\/2026\/07\/diM9tpwF2Lz85R8q85CT78.jpg\" alt=\"Google logo on a black background next to text reading 'Click to follow TechRadar'\"   loading=\"lazy\" data-new-v2-image=\"true\" data-original-mos=\"https:\/\/www.europesays.com\/france\/wp-content\/uploads\/2026\/07\/diM9tpwF2Lz85R8q85CT78.jpg\" data-pin-media=\"https:\/\/www.europesays.com\/france\/wp-content\/uploads\/2026\/07\/diM9tpwF2Lz85R8q85CT78.jpg\" class=\"rounded-[var(--image--border-radius,0)] pull-rightinline\"\/>\n<\/p>\n<p><\/a><\/p>\n<p id=\"elk-9a0f2444-a2d5-11f1-bc53-fd422e10046a\"><a data-analytics-id=\"inline-link\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJsWTJoeVlXUmhjaTVqYjIwb0FBUAE?hl=en-GB&amp;gl=GB&amp;ceid=GB%3Aen\" target=\"_blank\" data-url=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJsWTJoeVlXUmhjaTVqYjIwb0FBUAE?hl=en-GB&amp;gl=GB&amp;ceid=GB%3Aen\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-article-category=\"pro\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">Follow TechRadar on Google News<\/a> and <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.google.com\/preferences\/source?q=techradar.com\" target=\"_blank\" data-url=\"https:\/\/www.google.com\/preferences\/source?q=techradar.com\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-article-category=\"pro\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">add us as a preferred source<\/a> to get our expert news, reviews, and opinion in your feeds.<\/p>\n","protected":false},"excerpt":{"rendered":"Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminalsAI agents could install malware if they execute&hellip;\n","protected":false},"author":2,"featured_media":71706,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12919],"tags":[4953],"class_list":["post-71705","post","type-post","status-publish","format-standard","has-post-thumbnail","category-hermes","tag-hermes"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/posts\/71705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/comments?post=71705"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/posts\/71705\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/media\/71706"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/media?parent=71705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/categories?post=71705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/france\/wp-json\/wp\/v2\/tags?post=71705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}