Intelligence
AEV-2026-0039

Coding agents autonomously installed unclaimed packages named in genuine vendor agent facing documentation inside Fortune 500 networks

Alon Hertz's Data Became Code research resolved thousands of vendor agent facing documentation pages and found hundreds of install destinations naming packages and domains nobody controlled. Registering a small set with inert callbacks inside and prompting agents with nothing but a vendor's name, the team recorded a confirmed install and execution inside a Fortune 500 network's own infrastructure in under four minutes, a second within the hour, and further callbacks afterward, with parent process chains independently reported to trace to Claude, Codex and Hermes Agent sessions.

AESS 7.9 highObservedStatus: publishedEvent: 26 August 2026Execution AuthorityAgent IdentityAudit and Evidence

Affected

Organisation
unknown
Product
Coding agent sessions built on Claude, Codex and Hermes Agent, following genuine vendor agent facing documentation
Component
Install and setup instructions inside vendor agent facing documentation naming packages, domains or subdomains by a mutable identifier rather than a fixed artifact identity
Versions
unknown
Configurations
Five frontier model configurations and two agentic coding CLIs, each run 100 times against an identical, vendor name only prompt with no link to documentation and no mention of llms.txt; Autonomous discovery of a named vendor's own documentation and its install instructions, with no documentation URL supplied in the task

Execution authority facts

Fields the evidence does not establish are shown as unknown rather than guessed.

Intended task
Build and run a small project using a named vendor's own SDK, following that vendor's own documentation, per Hertz's own stated experimental prompt
Agent
Coding agent sessions independently reported to run on Claude, Codex and Hermes Agent
Delegating actor
Alon Hertz's own research team, issuing the controlled, vendor name only prompt as the experimental task
Action
Autonomously located a named vendor's own agent facing documentation, followed its install instruction, and installed a package the researchers had themselves registered under a name the documentation referenced but which nobody previously controlled
Target resource
A package, domain or subdomain named in a vendor's own genuine documentation, one of more than 237 such artifacts by Hertz's own count, or 227 by Ars Technica's independent count, that the scan found unclaimed
Environment
Corporate development environments inside Fortune 500, defense contractor and large technology company networks whose own infrastructure produced the recorded callbacks
Credentials used
unknown
Privileges available
Ordinary developer or build environment privileges sufficient to run a package manager install inside the host network
Authority presented
The named vendor's own genuine, unmodified documentation instructing an install by a bare package or domain name
Authority required
Confirmation that the specific artifact the install command resolved to was controlled by the named vendor, or by a party the vendor authorized
Applicable policy
unknown
Approval mechanism
none
Required approver
unknown
Independent approval
no
Action binding
The task principal's own instruction authorized following a named vendor's documentation in general terms; nothing bound that authorization to the specific package identity the install command later resolved to
Sequence context
Documentation discovery, install instruction location and package resolution and execution all occurred inside one autonomous agent run, with no human review step between locating the instruction and executing what it named

Impact

Consequence
material
Reach
systemic
Reversibility
reversible
Detectability
unknown
Propagation
observed
Recovery
Researcher controlled: the registered packages contained only an inert callback by the researchers' own design, with no destructive payload. This entry does not establish what, if anything, affected organisations did in response, since none is named and the research was disclosed rather than reported by any named affected party.

Evidence

Primary sources

Supporting sources

Reproduction status
Reported as a controlled, researcher run experiment reproduced across five frontier model configurations and two agentic CLIs at 100 runs each, per Hertz's own account. This session could not independently rerun the experiment and relies on Hertz's own account, corroborated across multiple independently phrased web search passes and independent secondary reporting, since direct fetch of medium.com and arstechnica.com was blocked in this session.
Evidence state
Observed

Known unknowns

  • The identity of the affected Fortune 500 companies and any other named or unnamed organisation whose infrastructure produced a callback. This entry does not identify them and treats them as unknown rather than guessing from context.
  • The exact five frontier model configurations and two agentic coding CLIs used, beyond Claude, Codex and Hermes Agent, which is the complete set this session could independently corroborate through Ars Technica's own independently reported parent process attribution.
  • Whether the discrepancy between Hertz's own stated counts, 8,565 files and more than 237 unclaimed artifacts, and Ars Technica's independently reported counts, 8,265 files, 120 sites and 227 install commands, reflects a filtering difference, a files versus commands distinction, a dataset revision or a reporting correction.
  • What action, if any, the affected organisations took after the callback, and whether any of them were notified directly by the researchers ahead of publication.

Limitations

  • Direct fetch of medium.com, the primary source, and of arstechnica.com, the independent corroborating account with the differing corpus counts, was blocked by this session's network egress policy on every attempted route. Every factual claim in this entry rests on corroboration across multiple independently phrased web search passes and independent secondary reporting rather than a direct read of either primary page, and an editor with unblocked network access should verify both directly.
  • This entry treats the Claude, Codex and Hermes Agent attribution as evidence that sessions built on those three products were among the agents whose behavior produced a confirmed execution, not as a claim covering every configuration, version or the default behavior of any one of the three.

Claim provenance