{
  "id": 4419190,
  "title": "Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks",
  "url": "https://urgent.news/2026/08/30/top-ai-tools-including-claude-codex-and-hermes-installed-suspicious",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-30T12:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/top-ai-tools-including-claude-codex-and-hermes-installed-suspicious-code-inside-corporate-networks"
  },
  "original_language": "en",
  "account": "New research has revealed that top AI tools like Claude, OpenAI's Codex, and Nous Research's Hermes have been found to install suspicious code within corporate networks. Cybercriminals are now able to exploit unclaimed llms.txt references on 120 domains, allowing AI agents to install malware if they execute outdated or hallucinated documentation commands. These \".txt\" files, containing information about AI agents, can be found on the websites of defense contractors, Fortune 500 organizations, and big tech companies. Among the 8,265 of these \".txt\" files, 120 were found to be pointing at non-existent packages and domains. Researchers registered some of these unclaimed names and hosted packages that would communicate with their servers when installed. In less than an hour, a Fortune 500 company started pinging these malicious packages, with numbers soon growing to \"a few dozen more.\" This demonstrates that cybercriminals can also carry out such attacks. To protect against this vulnerability, companies should clean up their documentation and restrict AI agents from treating it as executable instructions. While AI agents treating documentation as executable commands may not be resolved soon, organizations should consider the risks when granting AI agents permission to execute commands.",
  "summary": "There is a new class of \"squatting\" risks emerging right in front of us and it involves llms.txt and llms-full.txt documentation.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 4,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "We said a Claude Code subagent costs 436k tokens. A cleaner measurement says 54k — here is what fooled us",
        "url": "https://urgent.news/2026/08/29/we-said-a-claude-code-subagent-costs-436k-tokens-a-cleaner",
        "published": "2026-08-29T02:17:00.000Z"
      },
      {
        "outlet": "Techmeme",
        "title": "Anthropic will \"permanently\" raise weekly Claude Code limits by 25% on Sept. 14 for most plans, which will work out a 17% reduction, given the current 50% boost (@claudedevs)",
        "url": "https://urgent.news/2026/08/29/anthropic-will-permanently-raise-weekly-claude-code-limits-by-25-on",
        "published": "2026-08-29T18:05:01.000Z"
      },
      {
        "outlet": "XDA Developers",
        "title": "I gave Claude Code my own spinner verbs, and now my terminal sounds like me",
        "url": "https://urgent.news/2026/08/29/i-gave-claude-code-my-own-spinner-verbs-and-now-my-terminal-sounds",
        "published": "2026-08-29T20:00:15.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}