Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files

Security researchers have demonstrated that AI coding agents can be manipulated into executing malicious code by following instructions found in unverified llms.txt files. This vulnerability allows attackers to compromise Fortune 500 companies by registering abandoned package names and domains that the agents trust as authoritative documentation.

Edward Kiledjian @ekiledjian