Urgent.News

What's breaking now, across thousands of outlets.

AI

Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code — supply-chain attack via llms.txt guidance file illustrates how data has become code

Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code. This supply-chain attack, done via using data in public llms.txt guidance files, illustrates the dangers of data becoming code.

Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code — supply-chain attack via llms.txt guidance file illustrates how data has become code

Researchers successfully tricked AI agents from Fortune 500 companies into running arbitrary code through an llms.txt guidance file. This file, often hosted on a software product's website, contains instructions for AI agents on how to correctly scrape a website. The study, conducted by Pandex, discovered 237 references to non-existent or outdated software packages across 8,565 files.

These packages spanned various repositories including PyPI, npm, RubyGems, NuGet, crates.io, and Packagist. When an AI agent encounters the llms.txt file, it immediately knows how to operate the code, including the language, environment, and dependencies. Pandex created their own malware, which was successfully executed by AI agents within four minutes of being deployed.

This highlights the ease with which AI agents can be manipulated using llms.txt files. The researchers concluded that the distinction between data and code is blurring with the rise of agentic LLMs, making it increasingly difficult to distinguish between the two.

Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at tomshardware.com →

More in AI

More from Wednesday 2 September →