CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5687

As cited

Copy frozen at (site build).

ai security

AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

Researchers discovered that artificial intelligence (AI) coding agents from vendors including Anthropic, OpenAI, and Nous Research automatically installed packages from unregistered domain names and code repositories found in llms.txt configuration files hosted on corporate networks. The team scanned over 6,000 domains belonging to defense contractors, Fortune 500 companies, and Big Tech firms, identified 120 files pointing to unclaimed names, registered some domains, and received phone-home signals from multiple Fortune 500 companies within hours of hosting test packages. The researchers warn that AI agents treat vendor documentation as authoritative without verification, creating a supply chain attack surface comparable to past incidents like SolarWinds.

Why it matters: Security teams deploying AI coding agents at defense contractors, Fortune 500, and Big Tech companies face immediate risk of compromise through malicious package injection via configuration files that AI agents blindly trust and execute without human oversight.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary