watch your llms.txt...
2026-08-28 02:23:25.081537+02 by Dan Lyke 0 comments
Bwahahaha! Claude, Codex, and Hermes installed unowned code inside corporate networks
Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that werent registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company.
Via David Gerard @davidgerard@circumstances.run
this is comedy plutonium