AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
Summary
Researchers discovered that AI coding agents (automated systems that write and execute code) are installing malicious software on corporate networks by exploiting llms.txt files (configuration files that tell AI agents where to find code packages). The agents, including Claude and OpenAI's Codex, blindly trusted these files and installed code from unclaimed domains that the researchers had set up, causing machines at Fortune 500 companies to connect to the researchers' servers within an hour, showing the agents don't verify whether code sources are legitimate before executing them.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.schneier.com/blog/archives/2026/09/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate-networks.html
First tracked: September 4, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 92%