{
  "id": 5077374,
  "title": "Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code — supply-chain attack via llms.txt guidance file illustrates how data has become code",
  "url": "https://urgent.news/2026/09/02/researchers-easily-trick-fortune-500-companies-ai-agents-into-running",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-02T10:20:00.000Z",
  "source": {
    "name": "Tom's Hardware",
    "slug": "tom-s-hardware",
    "url": "https://www.tomshardware.com/tech-industry/artificial-intelligence/researchers-easily-trick-fortune-500-companies-ai-agents-into-running-arbitrary-code-supply-chain-attack-via-llms-txt-guidance-file-illustrates-how-data-has-become-code"
  },
  "original_language": "en",
  "account": "Researchers successfully tricked AI agents from Fortune 500 companies into running arbitrary code through an llms.txt guidance file. This file, often hosted on a software product's website, contains instructions for AI agents on how to correctly scrape a website. The study, conducted by Pandex, discovered 237 references to non-existent or outdated software packages across 8,565 files. These packages spanned various repositories including PyPI, npm, RubyGems, NuGet, crates.io, and Packagist. When an AI agent encounters the llms.txt file, it immediately knows how to operate the code, including the language, environment, and dependencies. Pandex created their own malware, which was successfully executed by AI agents within four minutes of being deployed. This highlights the ease with which AI agents can be manipulated using llms.txt files. The researchers concluded that the distinction between data and code is blurring with the rise of agentic LLMs, making it increasingly difficult to distinguish between the two.",
  "summary": "Researchers easily trick Fortune-500 companies' AI agents into running arbitrary code. This supply-chain attack, done via using data in public llms.txt guidance files, illustrates the dangers of data becoming code.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}