AEV-2026-0039
Coding agents autonomously installed unclaimed packages named in genuine vendor agent facing documentation inside Fortune 500 networks
Alon Hertz's Data Became Code research resolved thousands of vendor agent facing documentation pages and found hundreds of install destinations naming packages and domains nobody controlled. Registering a small set with inert callbacks inside and prompting agents with nothing but a vendor's name, the team recorded a confirmed install and execution inside a Fortune 500 network's own infrastructure in under four minutes, a second within the hour, and further callbacks afterward, with parent process chains independently reported to trace to Claude, Codex and Hermes Agent sessions.
Affected
- Organisation
- unknown
- Product
- Coding agent sessions built on Claude, Codex and Hermes Agent, following genuine vendor agent facing documentation
- Component
- Install and setup instructions inside vendor agent facing documentation naming packages, domains or subdomains by a mutable identifier rather than a fixed artifact identity
- Versions
- unknown
- Configurations
- Five frontier model configurations and two agentic coding CLIs, each run 100 times against an identical, vendor name only prompt with no link to documentation and no mention of llms.txt; Autonomous discovery of a named vendor's own documentation and its install instructions, with no documentation URL supplied in the task
Execution authority facts
Fields the evidence does not establish are shown as unknown rather than guessed.
- Intended task
- Build and run a small project using a named vendor's own SDK, following that vendor's own documentation, per Hertz's own stated experimental prompt
- Agent
- Coding agent sessions independently reported to run on Claude, Codex and Hermes Agent
- Delegating actor
- Alon Hertz's own research team, issuing the controlled, vendor name only prompt as the experimental task
- Action
- Autonomously located a named vendor's own agent facing documentation, followed its install instruction, and installed a package the researchers had themselves registered under a name the documentation referenced but which nobody previously controlled
- Target resource
- A package, domain or subdomain named in a vendor's own genuine documentation, one of more than 237 such artifacts by Hertz's own count, or 227 by Ars Technica's independent count, that the scan found unclaimed
- Environment
- Corporate development environments inside Fortune 500, defense contractor and large technology company networks whose own infrastructure produced the recorded callbacks
- Credentials used
- unknown
- Privileges available
- Ordinary developer or build environment privileges sufficient to run a package manager install inside the host network
- Authority presented
- The named vendor's own genuine, unmodified documentation instructing an install by a bare package or domain name
- Authority required
- Confirmation that the specific artifact the install command resolved to was controlled by the named vendor, or by a party the vendor authorized
- Applicable policy
- unknown
- Approval mechanism
- none
- Required approver
- unknown
- Independent approval
- no
- Action binding
- The task principal's own instruction authorized following a named vendor's documentation in general terms; nothing bound that authorization to the specific package identity the install command later resolved to
- Sequence context
- Documentation discovery, install instruction location and package resolution and execution all occurred inside one autonomous agent run, with no human review step between locating the instruction and executing what it named
Impact
- Consequence
- material
- Reach
- systemic
- Reversibility
- reversible
- Detectability
- unknown
- Propagation
- observed
- Recovery
- Researcher controlled: the registered packages contained only an inert callback by the researchers' own design, with no destructive payload. This entry does not establish what, if anything, affected organisations did in response, since none is named and the research was disclosed rather than reported by any named affected party.
Evidence
Primary sources
Supporting sources
- Researchers easily trick Fortune 500 companies' AI agents into running arbitrary code: supply chain attack via llms.txt guidance file illustrates how data has become code (Tom's Hardware)
- Researcher Alon Hertz Tricked Claude, Codex and Hermes Into Running Malware (Startup Fortune)
- Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files (GBHackers)
- AI Agents Execute Phantom Code: How llms.txt Files Let Claude, Codex and Hermes Infect Corporate Networks (WebProNews)
- Reproduction status
- Reported as a controlled, researcher run experiment reproduced across five frontier model configurations and two agentic CLIs at 100 runs each, per Hertz's own account. This session could not independently rerun the experiment and relies on Hertz's own account, corroborated across multiple independently phrased web search passes and independent secondary reporting, since direct fetch of medium.com and arstechnica.com was blocked in this session.
- Evidence state
- Observed
Known unknowns
- The identity of the affected Fortune 500 companies and any other named or unnamed organisation whose infrastructure produced a callback. This entry does not identify them and treats them as unknown rather than guessing from context.
- The exact five frontier model configurations and two agentic coding CLIs used, beyond Claude, Codex and Hermes Agent, which is the complete set this session could independently corroborate through Ars Technica's own independently reported parent process attribution.
- Whether the discrepancy between Hertz's own stated counts, 8,565 files and more than 237 unclaimed artifacts, and Ars Technica's independently reported counts, 8,265 files, 120 sites and 227 install commands, reflects a filtering difference, a files versus commands distinction, a dataset revision or a reporting correction.
- What action, if any, the affected organisations took after the callback, and whether any of them were notified directly by the researchers ahead of publication.
Limitations
- Direct fetch of medium.com, the primary source, and of arstechnica.com, the independent corroborating account with the differing corpus counts, was blocked by this session's network egress policy on every attempted route. Every factual claim in this entry rests on corroboration across multiple independently phrased web search passes and independent secondary reporting rather than a direct read of either primary page, and an editor with unblocked network access should verify both directly.
- This entry treats the Claude, Codex and Hermes Agent attribution as evidence that sessions built on those three products were among the agents whose behavior produced a confirmed execution, not as a claim covering every configuration, version or the default behavior of any one of the three.
Claim provenance
- independent-reporting
Direct fetch of medium.com was blocked in this session. The domain count, file counts, unclaimed artifact count, ecosystems, callback timing and experimental methodology are corroborated here across repeated, independently phrased web search passes converging consistently on the same figures and wording, rather than read directly from the primary post.
The Documentation Was Genuine. The Package It Authorized Belonged to Someone Else. - independent-reporting
Direct fetch of tomshardware.com was blocked in this session. Used, and corroborated against separate search passes, as an independent secondary account naming both Hertz's own corpus counts and Ars Technica's independently differing corpus counts, and as the basis for treating the two as distinct rather than reconciling them.
The Documentation Was Genuine. The Package It Authorized Belonged to Someone Else. - independent-reporting
Direct fetch of startupfortune.com was blocked in this session. Used as corroboration for the Claude, Codex and Hermes Agent parent process attribution Ars Technica's own account is independently reported to describe.
The Documentation Was Genuine. The Package It Authorized Belonged to Someone Else.
