Researchers found that more than 100 websites published llms.txt or llms-full.txt files that referenced unregistered package names or domains, creating a software supply-chain exposure for AI agents consuming machine-readable documentation. In a controlled proof of concept, the researchers registered several unclaimed names and received beaconing from automated installations at dozens of organizations, including Fortune 500 companies; telemetry linked activity to Anthropic Claude, OpenAI Codex, and Nous Research Hermes. One misconfigured site also directed users to live malware.
The findings illustrate how attackers can exploit AI agents' reliance on external developer documentation and public package repositories, including by claiming names suggested by model-generated or outdated instructions. This resembles the active Phantom Raven technique of registering hallucinated package names to deliver malicious payloads. Organizations should treat AI-agent development environments as supply-chain trust boundaries, validate package and domain ownership, restrict agent installation and execution rights, and isolate agents and projects through network-layer segmentation and sandboxing.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
The researchers identified at least one misconfigured website whose documentation directed human or AI visitors to live malware.
Parent-process chains captured in the proof-of-concept beacon telemetry indicated that Anthropic Claude, OpenAI Codex, and Nous Research Hermes coding agents were involved in executing content associated with the installations.
Within an hour of hosting the proof-of-concept packages, the researchers received a beacon from a Fortune 500 company. Subsequent telemetry recorded execution from a few dozen organizations, including additional Fortune 500 companies and startups.
The researchers registered several unclaimed package or domain names referenced by the documentation and hosted proof-of-concept packages configured to contact a researcher-controlled server when executed.
Researchers scanned 6,214 domains and identified 8,265 llms.txt or llms-full.txt files. They found 120 files on separate websites that referenced one or more unregistered package or domain names, creating an opportunity to supply content that AI agents could execute.
Threat actors in the active Phantom Raven campaign exploit generative AI tools that hallucinate nonexistent software package names, register those names in public repositories, and seed them with malicious payloads. Developer scripts or AI agents can then automatically retrieve the malicious dependencies into build pipelines.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcehelpnetsecurity.com
Open sourcellmstxt.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.