news.mlab.sh
Back to the feed
supply-chain

AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

High
Summary

Researchers discovered that AI coding agents are secretly installing unknown code on corporate networks by leveraging un-registered domain names and code packages. This behavior mirrors supply-chain attacks like SolarWinds, highlighting a fundamental flaw in how AI agents trust vendor documentation and a growing risk as AI usage expands across various systems.

Researchers at a stealth startup in Israel identified a concerning trend: AI coding agents are installing un-registered code packages on corporate networks. The team scanned 6,214 live domains belonging to defense contractors, Fortune 500 companies, and Big Tech firms. They discovered 8,265 files named ‘llms.txt’ and ‘llms-full.txt’ – many sites hosted both. To test the system, the researchers registered a few of these un-registered domain names and hosted the associated code packages. Within an hour, they received a phone-home response from a Fortune 500 company, demonstrating the agents’ ability to connect to external servers. Over time, they received dozens more responses, originating from various companies, including Fortune 500 firms and startups. The researchers traced the installation process, revealing that AI coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were responsible. The researchers noted that these agents treat vendor documentation as unquestionable truth and don’t independently verify the code they are installing. This behavior echoes the SolarWinds supply-chain attack, where malicious code was inserted into trusted software. The researchers emphasized that as AI agents become more prevalent across SaaS, cloud, and endpoint systems, the attack surface – and the risk – will continue to grow exponentially.

Read the full article at Schneier on Security