started · updated
AI security risks: Malicious code execution and crawler impersonation
Security researchers have identified critical vulnerabilities in how AI coding agents interact with website documentation. By exploiting the emerging llms.txt and llms-full.txt file standards, attackers can trick autonomous agents into installing malicious software.
Alon Hertz and a security research team discovered that many major organizations, including defense contractors and Fortune 500 companies, have documentation referencing unregistered software packages or domains. By registering these unclaimed names on public registries, researchers demonstrated that AI agents from Anthropic, OpenAI, and Nous Research would automatically download and execute the code. In one instance, a Fortune 500 company's agent executed a test package in less than four minutes.
Separately, security firm GreyNoise reported that threat actors are impersonating AI crawlers to hunt for exposed credentials. Automated scanners from 824 different IP addresses forged the names of 13 AI crawlers—including those from Anthropic, OpenAI, Google, and Perplexity—to search for sensitive configuration files and password stores on misconfigured web servers.
Entities
Alon Hertz · Anthropic · Google · GreyNoise · Nous Research · OpenAI · Perplexity
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] AI agents from Anthropic, OpenAI, and Nous Research installed unclaimed code during testing. www.sofx.com
- [○ 1 SOURCE] Security researchers found that AI coding agents can be tricked into executing malicious code via llms.txt files. www.sofx.com
- [○ 1 SOURCE] One Fortune 500 company's AI agent executed a researcher's package in less than four minutes. www.sofx.com
- [● 2 SOURCES] Forged crawler names included those belonging to Anthropic, OpenAI, Google, and Perplexity. ppc.land · cybernoz.com
- [● 2 SOURCES] Automated scanners from 824 addresses forged the names of 13 AI crawlers to hunt for credential files. ppc.land · cybernoz.com
- [● 4 SOURCES] The research involved examining 6,214 live domains belonging to defense contractors, Fortune 500 companies, and large technology businesses. mugglehead.com · nationalcybersecurity.com · www.sofx.com · canaltech.com.br
- [● 4 SOURCES] AI agents from Anthropic, OpenAI, and Nous Research were found to be susceptible to this exploit. mugglehead.com · nationalcybersecurity.com · www.sofx.com · canaltech.com.br
- [● 3 SOURCES] A Fortune 500 company executed a researcher's package in less than four minutes during testing. nationalcybersecurity.com · www.sofx.com · canaltech.com.br
- [● 3 SOURCES] Researchers found 237 install commands pointing to unregistered package names and web domains within the scanned files. nationalcybersecurity.com · www.sofx.com · canaltech.com.br
- [● 4 SOURCES] The vulnerability centers on llms.txt and llms-full.txt files, which provide machine-readable guides for AI agents. mugglehead.com · nationalcybersecurity.com · www.sofx.com · canaltech.com.br
- [● 4 SOURCES] Security researchers identified that AI coding agents can be tricked into installing malware via faulty website documentation. mugglehead.com · nationalcybersecurity.com · www.sofx.com · canaltech.com.br