A structural vulnerability in AI-driven automation allowed unverified code execution across networks of major global enterprises. Researchers from an Israeli startup analyzed over six thousand corporate domains belonging to technology giants and defense contractors, identifying critical flaws in text files designed for automated reading by large language models. This emerging pattern was created to provide structured website summaries to AI systems, but hundreds of these official documents contained outdated instructions with direct installation commands pointing to nonexistent libraries in official programming registries or to expired domains no longer owned by anyone.
To test the risk practically, specialists registered some of these abandoned domain names and hosted harmless proof-of-concept packages. Within an hour, computers from Fortune 500 companies executed the files and established callback connections to the experiment's servers. Process tracking revealed the involvement of advanced coding agents, including Claude from Anthropic, Codex from OpenAI, and Hermes from Nous Research, which interpreted institutional documentation as secure instructions and ran shell commands without validating package ownership. Because requests originate from authorized corporate tools using standard protocols, traditional endpoint security systems issue no alerts, opening gaps for ransomware, active malware, and complete takeover of corporate development environments.