Research · curated 10 Sep 2026

AI coding agents are recommending malware packages, and...

Coverage timeline

10 Sep 2026daily.dev

Single-source research — first reported, latest, and curated coincide.

Why it matters

AI coding agents that auto-install hallucinated or unowned packages create a supply-chain attack vector invisible to traditional CVE scanning, and this research demonstrates real Fortune 500 organizations already executing attacker-controlled code without human sign-off.

Israeli researchers scanned 6,214 domains belonging to defense contractors, Fortune 500, and tech firms, finding 120 sites whose llms.txt/llms-full.txt files pointed to unowned package names or domains. After registering some names and hosting beacon code, they received phone-home responses within hours from dozens of organizations whose AI coding agents (Claude, OpenAI Codex, Nous Research Hermes) read the documentation and executed the unowned code without human verification; at least one misconfigured site pointed to live malware. The write-up also notes attackers registering AI-hallucinated ('slopsquatted') package names so agents install malware.