Major tech companies are currently dealing with a huge security headache. A new research report claims that popular digital assistants, including Claude and Codex, have been tricked into downloading suspicious code directly onto corporate networks. Security researchers discovered that hackers can easily hide dangerous commands inside special website text files, which these smart tools then read and automatically run without any human approval.
Unclaimed website documentation files expose massive security risks
The problem starts with two simple documents known as llms.txt and llms-full.txt. A growing number of websites use these files to give artificial intelligence bots a clean summary of what is on their pages. However, things go wrong when these files contain outdated links or point to software packages that no longer exist.
Security researcher Alon Hertz looked at over 6,000 domains owned by defense contractors and Fortune 500 organizations. He found that 120 of these sites had text files linking to unregistered domains. If a cybercriminal registers one of these dead links and uploads malware to it, any AI reading the site might accidentally install that virus. During a controlled test, it took less than an hour for a Fortune 500 system to accidentally trigger the trap.
Don’t miss the best of The Mac Observer
Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.
According to the researchers, Claude, Codex from OpenAI, and Hermes from Nous Research all fell for the trick. Because these bots are built to follow directions, they treat whatever they read as a direct order. If an agent has permission to install software, it will simply run the bad command and infect the entire system.
To fix this vulnerability, companies need to regularly clean up their website documentation to ensure it only points to active and safe software. Experts also advise network administrators to stop giving smart bots the freedom to install packages without human permission. Until those rules change, businesses relying on autonomous coding tools remain at serious risk.

Discussion