Research · curated 10 Sep 2026
AI coding agents are recommending malware packages, and...
First reported daily.dev
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
AI coding agents that auto-install hallucinated or unowned packages create a supply-chain attack vector invisible to traditional CVE scanning, and this research demonstrates real Fortune 500 organizations already executing attacker-controlled code without human sign-off.
Israeli researchers scanned 6,214 domains belonging to defense contractors, Fortune 500, and tech firms, finding 120 sites whose llms.txt/llms-full.txt files pointed to unowned package names or domains. After registering some names and hosting beacon code, they received phone-home responses within hours from dozens of organizations whose AI coding agents (Claude, OpenAI Codex, Nous Research Hermes) read the documentation and executed the unowned code without human verification; at least one misconfigured site pointed to live malware. The write-up also notes attackers registering AI-hallucinated ('slopsquatted') package names so agents install malware.