Thursday, August 27, 2026
Tech Beat
Aug 27, 2026, 2:00 PMCybersecurity

Claude, Codex and Hermes Executed Unclaimed Packages Inside Corporate Networks

Researchers found 120 AI documentation files pointing to unclaimed packages and domains, leading Claude, Codex and Hermes to execute test code inside firms.

Listen to this briefingAudio briefing

Summary

On August 27, 2026, researchers at an unnamed Israeli startup disclosed a scan of 6,214 defense contractor, Fortune 500 and Big Tech domains. Among 8,265 llms.txt and llms-full.txt files, including sites hosting both formats, 120 sites contained 227 commands for nonexistent PyPI or npm packages or unclaimed domains. The team registered several names and served proof-of-concept packages that phoned home. A Fortune 500 company responded within an hour, followed by a few dozen Fortune 500 companies and startups. Parent-process tracing identified Anthropic’s Claude, OpenAI’s Codex and Nous Research’s Hermes. The three companies had not commented by publication.

The emerging files provide AI-readable website documentation, but shell-enabled agents treated installation instructions such as pip, npm and npx commands as authoritative. Researchers said HTTPS, official domains, trusted third parties and permitted package-manager traffic can make these executions appear legitimate to endpoint detection and proxies. Alon Hertz said the trust model fails because agents and supervisors accept vendor documentation without verifying package ownership.

Clerk’s legitimate website instructed agents to run “npx clerk-next-fix-auth-protection,” letting npm fetch and execute a package that someone had claimed for live malware. Clerk fixed the file and said systems already using a binary from @clerk/eslint-plugin were not threatened, but possible infections remain unconfirmed. Some faulty references predated AI and were apparently written by humans, while others may have resulted from AI hallucinations. The broader weakness resembles prompt injection but requires no initially malicious instruction, because abandoned package names or domains can be captured later.

Positives

  • Scanning 6,214 corporate domains exposed 120 vulnerable documentation files before more abandoned names could be weaponized.
  • Parent-process tracing connected proof-of-concept installations to Claude, Codex and Hermes, clarifying which agents followed the instructions.
  • Clerk removed the malicious package reference after researchers identified live malware behind clerk-next-fix-auth-protection.
  • Systems already using a binary from @clerk/eslint-plugin were not exposed to Clerk’s malicious replacement package.

Risks & concerns

  • The 120 misconfigured sites contained 227 commands directing agents toward nonexistent packages or unclaimed domains.
  • A Fortune 500 company contacted the researchers’ server within one hour, followed by a few dozen companies and startups.
  • Clerk’s npx instruction pointed to live malware that could execute without entering the package in a project dependency manifest.
  • Endpoint detection and corporate proxies may accept the activity because approved agents access legitimate package registries through normal developer commands.
  • Actual infections remain unclear, while any abandoned package or domain referenced by trusted documentation could be claimed later.
  • Anthropic, OpenAI and Nous Research had not responded by publication despite their agents appearing in the execution chains.
Primary sourceAI - Ars Technicahttps://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityAug 27

ATF Declares Major Cyber Incident as Qilin Claims Ransomware Attack

CybersecurityAug 27

Visa VVAH AI Patches Code Before Human Review

CybersecurityAug 26

Boston Scientific Cyberattack Disrupts Global Shipments and Order Processing