Security1 distinct publisher2 min readPublished
A scan of 6,214 corporate domains found 120 sites whose AI-facing docs point at code packages and domains nobody owns, and registering a few of those names produced installs traced back to Claude, Codex and Hermes agents inside real networks.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The mechanism is thinner than dependency confusion and does not need a typo. A vendor publishes an llms.txt or llms-full.txt file for machine readers. An agent fetches it, finds a package name or a domain, and installs or resolves it. If nobody ever registered that name, the first person who does becomes the vendor of record for every agent that reads the file [3]. Classic dependency confusion requires guessing an internal package name. Typosquatting requires the victim to mistype. Here the target publishes the exact string and, per researcher Alon Hertz, nothing in the chain checks it: "Agents treat vendor docs as ground truth and don't question them, and neither do the humans supervising them" [9].
The density is worth the arithmetic. 120 affected sites across 6,214 scanned domains is one in 52, or 1.9 percent [12]. The file count runs ahead of the domain count because many sites publish both variants, 8,265 files over 6,214 domains, about 1.33 per domain [13][2].
Response time is the part that matters operationally. The first phone-home landed inside an hour [5], and a few dozen followed from a handful of registered names [4][6]. The source does not say how many names the researchers claimed, so the yield per name cannot be computed. It also carries no calendar dates for the scan or the beacon window, only "within an hour" and "over time" [14].
What the beacon data proves is narrower than the framing around it. The parent-process chain identifies which agent spawned each install, Claude, OpenAI's Codex, and Nous Research's Hermes [7], without recording whether a human clicked approve on any of them [15]. Anthropic, OpenAI and Nous Research had not responded to comment requests at publication [8], so the question of whether these agents fetch and execute doc-sourced names without confirmation is open.
Whether a hostile actor got to those names first remains unconfirmed. Bruce Schneier's read is an unverified forecast: he expects this to be exploited and points at SolarWinds-style supply chain attacks [11]. Hertz makes the growth argument, that agents are multiplying across SaaS, cloud and endpoint faster than the guards that would cover them [10].
The cheap control sits with whoever owns the doc, because the outside scan and the inside audit are the same scan. Any reference in your own llms.txt that resolves to nothing is a name someone else can register, and the code lands on your readers' machines under your documentation's authority.
Ranked by verification strength, evidence, and original report placement.
Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500 companies and Big Tech companies.
The scan found 8,265 llms.txt and llms-full.txt files, with many sites hosting both an llms.txt and an llms-full.txt file.
120 of the files, each on a different site, pointed to one or more code packages or domain names that were not registered.
The researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to the researchers' server.
Within an hour, the researchers received a phone-home response from a Fortune 500 company.
Over time the researchers received a few dozen more phone-home responses, some from more Fortune 500 companies and others from startups.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Seven AI coding agents run attacker code named in a repository's own .git config2 distinct publishers
security
The nationalization argument is really a vendor-continuity memo1 distinct publisher
security
Schneier and Rafi put a near-term ceiling on how fast AI will break cryptography1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One relay, no primary record
Every figure in this story — 6,214 domains, 8,265 files, 120 sites, a few dozen callbacks — reaches us through a single blog post describing work by a startup that is not named and has published nothing we can read. The internal arithmetic holds and the method is plausible, but there is no report, no dataset, no affected company on the record, and no dates; the three agent vendors named in the attribution stayed silent before publication.
Convention published widely, consumed silently
What the beacons really measure is uptake. Thousands of these files sit on defense, Fortune 500 and Big Tech domains, and something inside those networks was already resolving them fast enough to install a stranger's package within the hour. The process ancestry puts three separate agent products at the scene, which points to normal workflow rather than an exotic configuration. The ceiling on this reading is that one unverified scan supplies both the publishing side and the consuming side.
SolarWinds is a large borrowed frame
The demonstration is genuinely clever and the mechanism is real, but the observed harm is a research beacon calling home from an unnamed set of networks, and the exposure is 120 sites out of 6,214 — under two percent. Reaching from there to a SolarWinds comparison, and from process ancestry to 'the humans supervising them don't question it either', is the commentary doing work the measurements do not do. Schneier's caution about future exploitation is fair; the framing arrives ahead of the evidence.
The finding is a stealth vendor's pitch line
The research belongs to a company still in stealth, and 'as they multiply, so does the supply-chain surface, and today's guards don't cover it' is precisely the sentence a firm selling the missing guard wants in circulation. Schneier has no commercial stake, but the story confirms a thesis he has argued for years, and he forwards the numbers as given rather than testing them. No affected company is named, which conveniently removes anyone with standing to contradict the account.
Clear on what was claimed, not on what happened
We can state with certainty who said what: the quotes, the counts and the attribution are unambiguous as reported. We cannot verify any of it. One publisher, one interested and anonymous source, sound arithmetic, and no route to the underlying evidence leaves the central question — how many real networks are exposed and for how long — open.